THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18635 (HIGH 7.2) — Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.7

[NVD] CVE-2026-18635 (HIGH 7.2) — Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.7

mednvdPublished 2026-08-11

CVE-2026-18635 CVSS: 7.2 HIGH Published: 2026-08-11T15:17:28.627

Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.77.2 evaluate this permission against the caller's org

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18635