CVE-2026-6290: Velociraptor Query() Plugin Misapplies Permissions To Orgs

Published Apr 15, 2026
·
Updated

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which they may not have access to. The user's permissions in the other org are the same as the permissions they have in the org containing the notebook.

Affected Software

3 affected components
Velocidex Velociraptor<0.76.3
go/www.velocidex.com/golang/velociraptor<=0.76.2
Rapid7 Velociraptor<0.76.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 0.76.3

Event History

Apr 15, 2026
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
Affected Software
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6290?

CVE-2026-6290 is considered a high severity vulnerability due to the unauthorized access it allows to all organizations using the query() plugin.

2

How do I fix CVE-2026-6290?

To fix CVE-2026-6290, upgrade to Velociraptor version 0.76.3 or later where the vulnerability is addressed.

3

What are the potential impacts of CVE-2026-6290?

The potential impacts include unauthorized data access and manipulation across all organizations by an authenticated user.

4

Who is affected by CVE-2026-6290?

CVE-2026-6290 affects all users of Velociraptor versions prior to 0.76.3 who utilize the query() plugin.

5

Is CVE-2026-6290 a remote vulnerability?

No, CVE-2026-6290 is not remote; it requires an authenticated user to exploit the issue with the query() plugin.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203