
├ CVE-2026-19072 — Velociraptor · Privilege escalation to SuperUser └ CVE-2026-93425 — Dokploy · Auth'd OS command injection
Signal is active with 4 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hunt bypassing any ACL checks that would normally be applied. This flaw can then be escalated to allow the "investigator" user to run arbitrary VQL statements as an administrator user on the Velociraptor server.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

├ CVE-2026-19072 — Velociraptor · Privilege escalation to SuperUser └ CVE-2026-93425 — Dokploy · Auth'd OS command injection

[CVE] CVE-2026-19072 [HIGH PRIORITY] #Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal 🔗 https://exploitgrid.net/cve/CVE-2026-19072

🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-61732 CVE-2026-97359 CVE-2026-97360 CVE-2026-19072 CVE-2026-93425 ..🧵👇

#schwachstellen Velociraptor-Lücke CVE-2026-19072 erlaubt Rechteausweitung bis zum Administrator #cve202619072 #dfir #velociraptor #vql https://cybersecurity-news.de/velociraptor-cve-2026-19072-rechteausweitung-administrator