---
cve: "CVE-2026-19200"
severity: "HIGH"
cvss: 8.9
epss: "0.2%"
vendor: "Rapid7"
kev: false
exploited: false
published: "2026-08-24 03:22:14"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-05T03:13:16+02:00"
---

# CVE-2026-19200

> 8.9 HIGH · 🧪 PoC

## Beschreibung

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- c0c9dd609140139efcb37c47e2afa79ed57e6c84 (Commit)

## BSI-Hinweise (deutsch)

- [Rapid7 Velociraptor: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-2974) — _BSI-Einstufung: hoch_
  Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rapid7 Velociraptor ausnutzen, um Dateien zu manipulieren, Sicherheitsmaßnahmen zu umgehen, Code auszuführen oder Berechtigungen zu erweitern.

## Referenzen

- <http://docs.velociraptor.app/announcements/advisories/cve-2026-19200/>
- <https://github.com/Velocidex/velociraptor/pull/4962>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-19200) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
