GHSA-qx94-26r3-gv6gMediumCVSS 4.1

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.

🔗 References (4)