THREAT OPS › Threat News › [NVD] CVE-2026-18635 (HIGH 7.2) — Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.7
[NVD] CVE-2026-18635 (HIGH 7.2) — Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.7
CVE-2026-18635 CVSS: 7.2 HIGH Published: 2026-08-11T15:17:28.627
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.77.2 evaluate this permission against the caller's org
Indicators of compromise
- CVE-2026-18635cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18635