What is CVE-2026-64954?
CVE-2026-64954: A vulnerability in Velociraptor allows users to schedule new collections via VQL queries without enforcing the required COLLECT_CLIENT permission. This occurs when a user runs a VQL query that resets the authorization provider, potentially granting unauthorized scheduling access. Affected users should apply the latest security update and review VQL permissions immediately.
Azərbaycanca: CVE-2026-64954: Velociraptor platformasında VQL sorğuları vasitəsilə yeni kolleksiyalar planlaşdırılarkən COLLECT_CLIENT icazəsinin yoxlanılmaması zəifliyi aşkarlanıb. Bu, avtorizasiya təminatçısını sıfırlayan VQL sorğusunu işlədə bilən istifadəçiyə icazəsiz kolleksiya planlaşdırmağa imkan verir. Təsirə məruz qalan istifadəçilər dərhal ən son təhlükəsizlik yeniləməsini tətbiq etməli və VQL icazələrini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What permission issue does CVE-2026-64954 cause in the Velociraptor platform?
This vulnerability causes the failure to enforce the COLLECT_CLIENT permission when scheduling new collections via VQL queries.
How can a user exploit CVE-2026-64954 to perform an unauthorized operation?
A user can schedule unauthorized collections by running a VQL query that resets the authorization provider.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.