Authenticated Identity Spoofing Vulnerability in Velociraptor
Rapid7 Velociraptor versions prior to 0.77.2 are affected by an authenticated identity-spoofing vulnerability, CVE-2026-18972, that may allow unauthorized access or impersonation within the platform.
CVE search metadata
CVE search record: CVE-2026-18972. Severity: critical. CVSS: 9.6. KEV: no. Product: Velociraptor. Brief: Authenticated Identity Spoofing Vulnerability in Velociraptor. Brief link: https://feed.craftedsignal.io/briefs/2026-08-velociraptor-auth-bypass/
Rapid7 has disclosed a security vulnerability in Velociraptor, an endpoint visibility and incident response platform. The vulnerability, tracked as CVE-2026-18972, is classified as an authenticated identity-spoofing flaw. It affects all versions of Velociraptor prior to 0.77.2. The vulnerability allows an authenticated user to perform identity-spoofing, which may lead to unauthorized actions or elevated privileges within the platform's management console or communication protocol between agents and the server. Because Velociraptor is frequently used for high-privileged forensic tasks, the potential impact of an authenticated attacker successfully masquerading as a different user or administrator is significant for internal security operations. Organizations utilizing Velociraptor should prioritize upgrading to version 0.77.2 or later.
Impact
Successful exploitation could allow an authenticated attacker to perform unauthorized operations, potentially impacting the integrity of incident response data or allowing for the manipulation of endpoint collection tasks. The number of affected deployments is estimated to be significant among organizations using Velociraptor for forensic monitoring and live response, posing a risk to the security of the internal management network if the Velociraptor server itself is compromised.
Recommendation
- Upgrade all Velociraptor server and agent deployments to version 0.77.2 or later immediately.
- Audit access logs for the Velociraptor management console and API endpoints for signs of unexpected account impersonation or anomalous login patterns.
- Review all custom forensic VQL queries and tasks initiated within the environment around the time of the update to ensure no unauthorized configurations were injected.
Immediate actions
Upgrade Velociraptor to version 0.77.2 or later