CVE-2026-6290 Details
Description
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which they may not have access to. The user's permissions in the other org are the same as the permissions they have in the org containing the notebook.
A vulnerability exists in the Velociraptor query() plugin in versions prior to 0.76.3. This vulnerability allows an authenticated GUI user to access all organizations using the current ACL token. Users with access to one organization can execute VQL queries on other organizations through the query() plugin in a notebook cell, potentially accessing data they are not authorized to. The permissions in the accessed organization mirror those in the user's original organization.
Users can upgrade to Velociraptor version 0.76.3 or 0.75.8, depending on their current version. Alternatively, the query() plugin can be disabled by adding it to the denied_plugins list in the server.config.yaml file.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.velociraptor.app/announcements/advisories/cve-2026-6290/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rapid7 velociraptor | < 0.76.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Initial Analysis | [email protected] |
| Apr 15, 2026 | New CVE Received | [email protected] |