CVE-2026-19583

Velociraptor: Incorrect Permission Assignment for Critical Resource (CVE-2026-19583)

criticalEPSS 0.6 %

Beschreibung

Velociraptor erlaubt es, einige sensible Artefakte durch zusätzliche Berechtigungen zu sperren. Beispielsweise erfordert das Linux.Sys.BashShell-Artefakt die EXECVE-Berechtigung zur Planung, da es willkürlichen Befehlsausführungen auf Endpunkten ermöglicht. Eine solche Überprüfung wurde jedoch für Client-Monitoring-Artefakte nicht implementiert. Darüber hinaus gab es keine Anforderung, dass Client-Monitoring-Artefakte den CLIENT_EVENTS-Typ tragen müssen. Dies erlaubt jedem Benutzer, der Client-Monitoring-Artefakte planen kann, auch sonst eingeschränkte Artefakte (wie Linux.Sys.BashShell) zu planen.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.9
Quelle: cna-v3
46.8 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-10 02:58 UTC
CWE-732

Weakness-Klassen (CWE)

  • CWE-732Class

    Incorrect Permission Assignment for Critical Resource

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-11 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-19583","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…{"id":"CVE-2026-19583","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. CVE Modified2026-09-10 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-19583","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-10 03:16 UTC· cve@rapid7.com
    • Description: Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
    • CWE: CWE-732
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/19xxx/CVE-2026-19583.json">CVE-2026-19583</a>

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Rapid7

    Velociraptor< 0.77.2

    gefixt in 0.77.2

Quellen & Referenzen

IDCVE-2026-19583