Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Inspect the backup zip before restoring it to ensure it does not include malicious notebook contents. Do not automatically restore backup from untrusted sources.
References
History
Thu, 10 Sep 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored. | |
| Title | Velociraptor VQL injection during notebook restore from backup | |
| Weaknesses | CWE-1336 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-09-10T03:00:00.939Z
Reserved: 2026-08-11T23:11:25.332Z
Link: CVE-2026-19584
No data.
Status : Received
Published: 2026-09-10T03:17:00.063
Modified: 2026-09-10T03:17:00.063
Link: CVE-2026-19584
No data.
OpenCVE Enrichment
No data.