What is CVE-2026-64952?
CVE-2026-64952: The hunt_delete() VQL function in Velociraptor misapplied permission checks, allowing hunt deletion with only the COLLECT_CLIENT permission (typically assigned to the 'investigator' role) instead of requiring 'DELETE_RESULTS' (usually for administrators). Organizations should review role permissions and apply the relevant patch to prevent unauthorized hunt deletion.
Azərbaycanca: CVE-2026-64952: Velociraptor platformasında hunt_delete() VQL funksiyası səhv icazə yoxlaması tətbiq edib. Bu, yalnız 'investigator' roluna aid COLLECT_CLIENT icazəsi ilə hunt-ların silinməsinə imkan verir, halbuki 'DELETE_RESULTS' icazəsi (adətən 'administrator'lara məxsusdur) tələb olunmalıdır. Təşkilatlar, xüsusilə az imtiyazlı istifadəçi rolları üçün icazə konfiqurasiyalarını nəzərdən keçirməli və bu boşluğu aradan qaldıran yeniləməni tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Velociraptor
FAQ1
What misapplied permission check does CVE-2026-64952 involve in the Velociraptor platform?
The vulnerability involves the hunt_delete() VQL function misapplying permission checks, allowing hunt deletion with only the COLLECT_CLIENT permission (associated with the 'investigator' role) instead of requiring the 'DELETE_RESULTS' permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.