CVE-2026-19583
Velociraptor: Incorrect Permission Assignment for Critical Resource (CVE-2026-19583)
Beschreibung
Velociraptor erlaubt es, einige sensible Artefakte durch zusätzliche Berechtigungen zu sperren. Beispielsweise erfordert das Linux.Sys.BashShell-Artefakt die EXECVE-Berechtigung zur Planung, da es willkürlichen Befehlsausführungen auf Endpunkten ermöglicht. Eine solche Überprüfung wurde jedoch für Client-Monitoring-Artefakte nicht implementiert. Darüber hinaus gab es keine Anforderung, dass Client-Monitoring-Artefakte den CLIENT_EVENTS-Typ tragen müssen. Dies erlaubt jedem Benutzer, der Client-Monitoring-Artefakte planen kann, auch sonst eingeschränkte Artefakte (wie Linux.Sys.BashShell) zu planen.
Metriken
Weakness-Klassen (CWE)
CWE-732Class
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-09-11 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-19583","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-19583","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-09-10 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-19583","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-10 03:16 UTC· cve@rapid7.com
- Description: Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
- CWE: CWE-732
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/19xxx/CVE-2026-19583.json">CVE-2026-19583</a>
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
Rapid7
Velociraptor< 0.77.2
gefixt in 0.77.2