What is CVE-2026-18635?
CVE-2026-18635 is a vulnerability in Velociraptor's VQL `query()` plugin due to improper permission checks. It allows users with the IMPERSONATE permission (typically administrators) to execute VQL queries in the context of a different org or user. Users are advised to upgrade to version 0.77.2 or later immediately.
Azərbaycanca: Velociraptor platformasında aşkarlanan CVE-2026-18635 zəifliyi, `query()` VQL plugin-ində icazə yoxlanışının düzgün aparılmaması ilə bağlıdır. Bu, administrator səviyyəli İMPERSONATE icazəsi olan istifadəçilərə digər təşkilat və ya istifadəçi kontekstində VQL sorğuları icra etməyə imkan verir. İstifadəçilərə dərhal 0.77.2 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: shared vendor: Velociraptor
FAQ2
Which platform is affected by CVE-2026-18635?
The vulnerability exists in the VQL `query()` plugin of the Velociraptor platform.
What specific permission is required to exploit this vulnerability?
Exploiting this vulnerability requires the administrator-level IMPERSONATE permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.