CVE-2026-77798: Velociraptor Authenticated Denial of Service
Published Sep 24, 2026
·Updated
Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.
Affected Software
1 affected component
Velocidex Velociraptor
Event History
Sep 24, 2026
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can trigger this issue?
An authenticated user can trigger the deadlock. The vulnerability does not require user interaction and is reachable over the network.
2
What is the impact of successful exploitation?
Successful exploitation can cause a denial of service through a deadlock in the user management module. The provided severity vector indicates availability impact only, with no stated confidentiality or integrity impact.
3
Is an unpatched deployment exposed by default?
The available data confirms that authenticated users may trigger the issue, but it does not state whether any particular default configuration enables the vulnerable condition.