Critical SEVERITY — Vulnerability

CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be gated by additional permissions.

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also

Platform
Ubuntu Server
CVE Record
CVE-2026-19583
CVSS Score
9.9/10
Published
10 September 2026
Views
19
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).

Assessment

  • CVE: CVE-2026-19583
  • CVSS base score: 9.9
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched

Ubuntu Server — Related Advisories

VIEW ALL →