THREAT OPS › Threat News › [NVD] CVE-2026-18652 (MEDIUM 6.5) — Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes
[NVD] CVE-2026-18652 (MEDIUM 6.5) — Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes
CVE-2026-18652 CVSS: 6.5 MEDIUM Published: 2026-08-12T10:17:16.940
Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes.
In particular, a user with read access to the roo
Indicators of compromise
- CVE-2026-18652cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18652