CVE-2026-19584: Velociraptor VQL injection during notebook restore from backup

Published Sep 10, 2026
·
Updated

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOKEDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

Affected Software

1 affected component
Velociraptor Velociraptor

Event History

Sep 10, 2026
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can plant the malicious content, and when does it execute?

A user with NOTEBOOK_EDITOR permission can place a malicious VQL query in notebook cell content. The query is evaluated at elevated permissions only if a backup containing that notebook is later restored.

2

Are default deployments affected?

The described attack path involves Velociraptor's daily notebook backup feature, which is enabled by default. Exposure requires a notebook backup to be restored after the malicious content has been included in it.

3

What permissions are needed for exploitation?

The attacker needs NOTEBOOK_EDITOR permission to create or modify notebook cell content. The CVSS vector also indicates that user interaction is required, consistent with a backup restore being needed to trigger evaluation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203