Security Advisory

CVE-2026-18638

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 15:00:53
Last updated 2026-08-11 17:22:44
Assigner rapid7
CVSS score 6.5
State PUBLISHED

Description

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.