CVE-2026-18348: Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins
Missing authorization check in the uploadazure, uploadsftp, and uploadsmb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18348?
The severity of CVE-2026-18348 is classified as medium with a score of 4.1.
How do I fix CVE-2026-18348?
To fix CVE-2026-18348, ensure that proper authorization checks are implemented in the upload_azure, upload_sftp, and upload_smb VQL plugins.
What systems are affected by CVE-2026-18348?
CVE-2026-18348 affects instances of the Velociraptor server that utilize the specified VQL plugins.
Who can exploit CVE-2026-18348?
An authenticated user with analyst-role permissions on the Velociraptor server can exploit CVE-2026-18348.
What are the potential impacts of CVE-2026-18348?
CVE-2026-18348 can allow an authenticated user to bypass NETWORK ACLs and initiate attacker-controlled outbound network connections.