{"id":"CVE-2026-77798","title":"Velociraptor contains a deadlock condition that may be triggered by authenticated users","summary":"Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-833"],"vendor":"Rapid7","product":"Velociraptor","affected":["Velociraptor < 0.77.2"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T15:17:38.277","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77798","references":[{"url":"http://docs.velociraptor.app/announcements/advisories/cve-2026-7798/","label":"cve@rapid7.com"},{"url":"https://github.com/Velocidex/velociraptor/commit/b64d915422da2e8366781bea2b5c5e6808df829c","label":"cve@rapid7.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-24T14:48:32.322715Z"},"ingestedAt":"2026-09-24T14:44:21.325Z","slug":"CVE-2026-77798","body":"## Overview\n\nVelociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}