Vulnerability Description
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- http://docs.velociraptor.app/announcements/advisories/cve-2026-18348/
- https://github.com/Velocidex/velociraptor/commit/48824fb51a2bdba832abc281e719ecb
FAQ
What is CVE-2026-18348?
CVE-2026-18348 is a vulnerability with a CVSS score of 4.1 (MEDIUM). Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from th...
How severe is CVE-2026-18348?
CVE-2026-18348 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18348?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.