CVE-2026-19200Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-24: 2Technical Details · 2026-08-24: 108-24
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • ADK Cyber@ADKCyber
    Disclosure

    Velociraptor users: CVE-2026-19200 (CVSS 8.9) impacts the verify() VQL function. Review your deployment for potential issues. https://nvd.nist.gov/vuln/detail/CVE-2026-19200 https://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/r5128SgLc2

    Post summary

    The tweet announces CVE‑2026‑19200, a high‑severity flaw affecting Velociraptor’s verify() VQL function, urging users to review deployments and providing a link to the NVD entry.

    0101045
    93 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Rapid7 Velociraptor (CVE-2026-19200) https://vuldb.com/vuln/394587

    Post summary

    A new CVE (CVE-2026-19200) affecting Rapid7 Velociraptor has been disclosed with an increased severity rating, with no additional exploitation or patch details provided.

    00000135
    2.3K followersView on X

Explore more