THREAT OPS › Threat News › [NVD] CVE-2026-64954 (HIGH 8.2) — Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider.
This allows
[NVD] CVE-2026-64954 (HIGH 8.2) — Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows
CVE-2026-64954 CVSS: 8.2 HIGH Published: 2026-08-12T05:19:17.893
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider.
This allows a user who can run arbitrary VQL (usually with the "an
Indicators of compromise
- CVE-2026-64954cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64954