Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6290

Опубликовано: 15 апр. 2026
Источник: nvd
CVSS3: 8
CVSS3: 9.1
EPSS Низкий

Описание

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which they may not have access to. The user's permissions in the other org are the same as the permissions they have in the org containing the notebook.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*
Версия до 0.76.3 (исключая)

EPSS

Процентиль: 13%
0.00224
Низкий

8 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 9.1
github
4 месяца назад

Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token

EPSS

Процентиль: 13%
0.00224
Низкий

8 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-863