---
id: CVE-2026-18652
title: "Velociraptor allows reading Stacked result sets from the GUI.\_ Velociraptor's multi-tenant design stores sub orgs within the datastore directory.\_The path requested by the GUI is not correctly checked against the prefix deny list, allowi…"
summary: "Velociraptor allows reading Stacked result sets from the GUI.\_ Velociraptor's multi-tenant design stores sub orgs within the datastore directory.\_The path requested by the GUI is not correctly checked against the prefix deny list, allowi…"
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
published: '2026-08-12'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18652'
references:
  - url: 'http://docs.velociraptor.app/announcements/advisories/cve-2026-18652/'
    label: cve@rapid7.com
tags:
  - nvd
epss: 0.00274
epssPercentile: 0.20071
ingestedAt: '2026-08-24T06:59:08.750Z'
---

## Overview

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes.

In particular, a user with read access to the root org can access result sets from child orgs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
