CVE-2026-18348Disclosure

LOWCVSS 4.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-11); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-11: 1Mentions · 2026-08-15: 1Technical Details · 2026-08-11: 108-1108-15
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-111
Disclosure1
2026-08-151
General1
Full discourse2 posts
  • Hexucated@hexucated
    General

    It's been a while .... 3 new CVEs in @velocidex by @rapid7 CVE-2026-18860 CVE-2026-18640 CVE-2026-18348 https://t.co/yEWuS2qN6i

    Post summary

    The tweet simply announces three new CVEs for Velocidex, offering no further information on exploitation, patches, or technical characteristics.

    01031704
    838 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18348 Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled ou… https://www.cve.org/CVERecord?id=CVE-2026-18348

    Post summary

    The text announces CVE‑2026‑18348, describing a missing authorization check in specific VQL plugins that could allow an attacker to control operations as an authenticated analyst‑role user, but contains no proof‑of‑concept, exploit tool, active exploitation claim, patch information, or debunking statement.

    00000687
    57.9K followersView on X

Explore more