Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-19584

Опубликовано: 10 сент. 2026
Источник: nvd
CVSS3: 7.7
EPSS Низкий

Описание

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

EPSS

Процентиль: 8%
0.0019
Низкий

7.7 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.7
github
19 дней назад

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

EPSS

Процентиль: 8%
0.0019
Низкий

7.7 High

CVSS3

Дефекты

CWE-94