CVE-2026-5329Disclosure(rapid7 / velociraptor)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring message with a malicious queue name. The server handler that receives client monitoring messages does not sufficiently validate the queue name supplied by the client, allowing a rogue client to write arbitrary messages to privileged internal queues. This may lead to remote code execution on the Velociraptor server. Rapid7 Hosted Velociraptor instances are not affected by this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • velociraptor

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
velociraptor

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-09: 2Technical Details · 2026-04-09: 204-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5329: HIGH] Rapid7 Velociraptor versions prior to 0.76.2 have an input validation flaw allowing an authenticated remote attacker to write to internal server queues leading to potential code execution.#cve,CVE-2026-5329,#cybersecurity https://cvefind.com/CVE-2026-5329

    Post summary

    The post announces a new vulnerability (CVE‑2026‑5329) in Rapid7 Velociraptor, detailing its nature and potential impact, but provides no PoC, exploit code, or patch information.

    0000099
    619 followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    CVE-2026-5329 Velociraptor improper input validation in client message handler -- https://docs.velociraptor.app/announcements/advisories/cve-2026-5329

    Post summary

    The advisory announces a CVE‑2026‑5329 vulnerability—improper input validation in Velociraptor’s client message handler—without any proof of concept, exploit code, active exploitation evidence, or patch details provided in the text.

    00000124
    3.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprapid7velociraptor---

Explore more