CVE-2026-18652: Velociraptor STACK Type Download Path Bypasses Denied Prefix Check

Published Aug 12, 2026
·
Updated

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes.

In particular, a user with read access to the root org can access result sets from child orgs.

Affected Software

1 affected component
Velociraptor

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Fix/verify that the GUI path requested for stacked result sets is checked correctly against the configured prefix deny list, and that result sets are blocked from reading data under denied prefixes across child orgs.

    Velociraptor GUI (multi-tenant org boundary checks) prefix deny list enforcement = Ensure the GUI requested path is correctly validated against the deny list (deny access when the requested path resolves under denied prefixes)
  2. Compensating control

    Use an external control (e.g., datastore access restrictions) so that users with root org read access cannot access stacked result sets from child orgs outside the intended org boundary.

Event History

Aug 12, 2026
CVE Published
via MITRE·09:56 AM
Data Sourced
via MITRE·09:56 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-18652?

The severity of CVE-2026-18652 is rated as medium with a score of 4.9.

2

What vulnerability does CVE-2026-18652 describe?

CVE-2026-18652 describes a vulnerability in Velociraptor that allows reading Stacked result sets due to incorrect prefix checks.

3

How can I mitigate CVE-2026-18652?

To mitigate CVE-2026-18652, ensure that prefix checks are correctly implemented to restrict access to denied prefixes.

4

Which software is affected by CVE-2026-18652?

CVE-2026-18652 affects the Velociraptor software.

5

When was CVE-2026-18652 published?

CVE-2026-18652 was published on August 12, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203