CVE-2026-6290: Velociraptor Query() Plugin Misapplies Permissions To Orgs
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which they may not have access to. The user's permissions in the other org are the same as the permissions they have in the org containing the notebook.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.76.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6290?
CVE-2026-6290 is considered a high severity vulnerability due to the unauthorized access it allows to all organizations using the query() plugin.
How do I fix CVE-2026-6290?
To fix CVE-2026-6290, upgrade to Velociraptor version 0.76.3 or later where the vulnerability is addressed.
What are the potential impacts of CVE-2026-6290?
The potential impacts include unauthorized data access and manipulation across all organizations by an authenticated user.
Who is affected by CVE-2026-6290?
CVE-2026-6290 affects all users of Velociraptor versions prior to 0.76.3 who utilize the query() plugin.
Is CVE-2026-6290 a remote vulnerability?
No, CVE-2026-6290 is not remote; it requires an authenticated user to exploit the issue with the query() plugin.