Velociraptor vulnerabilities
CVEs whose affected-version data names the Velociraptor package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-19584High· 7.7Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature
Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…
▾ TwilightRapid7 · VelociraptorEPSS 0.19%via NVD
CVE-2026-19583Critical· 9.9Velociraptor Required Permissions bypass by using client monitoring queries
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howe…
▾ MidnightRapid7 · VelociraptorEPSS 0.60%via CVEORG