CVE-2026-19200: Velociraptor Analyst overwrites live built-in artifacts through verify()

Published Aug 24, 2026
·
Updated

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOKEDIT permission (e.g. an analyst role) to be able to call this function.

Affected Software

1 affected component
Velociraptor

Event History

Aug 24, 2026
CVE Published
via MITRE·03:22 AM
Data Sourced
via MITRE·03:22 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any user with the NOTEBOOK_EDIT permission can exploit it. This includes users assigned an analyst role, if that role grants NOTEBOOK_EDIT.

2

What does an attacker need to do to exploit it?

The attacker needs authenticated access with NOTEBOOK_EDIT permission and must be able to invoke the verify() VQL function. No additional artifact-modification permission is required.

3

What is the impact of successful exploitation?

An attacker can overwrite existing live built-in artifacts in the global artifact repository. This can affect confidentiality, integrity, and availability across the affected security scope.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203