THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-64954 (HIGH 8.2) — Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows

[NVD] CVE-2026-64954 (HIGH 8.2) — Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows

mednvdPublished 2026-08-12

CVE-2026-64954 CVSS: 8.2 HIGH Published: 2026-08-12T05:19:17.893

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider.

This allows a user who can run arbitrary VQL (usually with the "an

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64954