External risk intelligence

Velociraptor Hunt Object Allows Arbitrary VQL Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-19072

Velociraptor is an endpoint visibility and incident response tool typically deployed within internal corporate networks for security operations. While the server component can be configured for remote access by investigators, it is not a public-facing service by design, making internet exposure conditional on specific organizational deployment choices rather than standard usage.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Velociraptor, an endpoint visibility tool, allows users with investigative privileges to execute arbitrary commands as an administrator by bypassing security checks. This could enable unauthorized access and control over the Velociraptor server.

  • Allows basic users to run admin commands.
  • Critical for protecting server and data integrity.
  • Confirm relevance and assess exposure immediately.

Attack Path

How an attacker could exploit the issue

An attacker with investigator privileges can target the hunt object within Velociraptor. By manipulating an internal field meant to store pre-compiled VQL, the attacker can bypass normal access controls and inject arbitrary VQL statements. This allows them to execute commands with administrator-level permissions on the Velociraptor server.

  • Investigator role required to schedule hunts.
  • Setting internal `compiled_collector_args` field.
  • Arbitrary code execution as administrator.

Live Threat

Current exploitation, exposure, and threat context

An investigator user could manipulate compiled VQL statements to execute arbitrary VQL as an administrator on the Velociraptor server when supported by the advisory.

  • Administrator credentials and server control.
  • API calls to schedule hunts.
  • Arbitrary VQL execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Velociraptor server owner, likely a security operations or platform team, must identify all deployed Velociraptor instances. Once identified, determine reachability and business criticality to prioritize remediation, involving vendor coordination if necessary.

  • Identify all Velociraptor instances.
  • Confirm reachability and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Velociraptor and what is it used for?

Velociraptor is an open-source endpoint visibility and digital forensics tool. Security teams use it to query vast numbers of endpoints across a network, allowing them to hunt for threats, collect system artifacts, and perform incident response actions centrally from a management server.

What does CVE-2026-19072 mean in plain English?

This vulnerability involves an Improper Access Control flaw (CWE-164) and an unauthorized data modification issue (CWE-1269). It occurs because the software incorrectly allows low-privileged users to modify internal settings typically reserved for the system. By injecting unauthorized commands into these settings, a user can trick the server into running code with full administrative permissions.

How does an attacker trigger this vulnerability?

An attacker must hold at least an 'investigator' role to schedule hunts within the platform. The flaw is triggered by using a specific API call to manipulate the 'compiled_collector_args' field, which is intended for internal use only. Simply viewing hunts or accessing the system without the ability to schedule or modify these specific hunt objects does not trigger the vulnerability.

Do I need to worry if my Velociraptor server is internal?

According to Halo Surface Signal, Velociraptor is primarily designed for internal networks. While it is not typically public-facing, you should still evaluate your specific deployment. If your organization has configured remote access for investigators, that could increase the risk of an attacker leveraging this flaw, even if the service is not exposed to the public internet.

How should I respond to this threat?

Start by identifying all instances of Velociraptor currently running in your environment. Prioritize these based on their reachability and the sensitivity of the data they handle. Work with your security team to confirm if any investigator accounts have been compromised or used suspiciously, and coordinate with the vendor to apply the necessary updates or security configurations.

References