Security Advisory

CVE-2026-18636

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 14:40:12
Last updated 2026-08-11 19:43:56
Assigner rapid7
CVSS score 6.8
State PUBLISHED

Description

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.