What is CVE-2026-18652?
CVE-2026-18652 is a vulnerability in Velociraptor that allows unauthorized reading of Stacked result sets via the GUI. Due to improper path validation against a prefix deny list in its multi-tenant design, result sets from restricted prefixes can be accessed. Users are advised to restrict GUI queries and apply the relevant update.
Azərbaycanca: CVE-2026-18652, Velociraptor platformasında GUI vasitəsilə Stacked result set-lərə icazəsiz oxuma imkanı yaradan zəiflikdir. Multi-tenant mühitlərdə path yoxlamasındakı boşluq səbəbindən sub təşkilatların məlumatlarına giriş əldə edilə bilər. İstifadəçilərə GUI üzərindən gələn sorğuları ciddi şəkildə məhdudlaşdırmaq və yeniləmə tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which environments does CVE-2026-18652 in Velociraptor pose a risk?
CVE-2026-18652 poses a risk in multi-tenant environments of the Velociraptor platform, allowing unauthorized reading of data from sub-organizations.
What is the root cause of this vulnerability?
The vulnerability is caused by improper path validation when accessing Stacked result sets via the GUI.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.