Rapid7 Velociraptor versions earlier than 0.77.2 were found to contain 15 vulnerabilities, including six high-severity flaws and one critical issue, that can let attackers bypass authentication and authorization controls and compromise system data and configurations. The weaknesses span authentication bypass, privilege escalation, security restriction bypass, spoofing, tampering, information disclosure, and arbitrary file write, expanding the attack surface for organizations using the digital forensics and incident response platform.
One of the newly disclosed issues, CVE-2026-18972, allows an authenticated attacker to spoof another GUI user's identity by sending requests with the Grpc-Metadata-USER header, potentially escalating from a low-privileged account to administrator access and enabling account takeover. The flaw is classified as CWE-290 and carries a high-severity CVSS:3.1 rating of AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N; defenders are advised to upgrade affected deployments to Velociraptor 0.77.2 or later in line with the vendor's security guidance.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-18860 was newly received by cve@rapid7.com as a high-severity authorization flaw in Rapid7 Velociraptor versions earlier than 0.77.2. The issue lets a child-org administrator abuse incorrect ORG_ADMIN permission checks during org deletion to delete other orgs without ROOT org administrator privileges.
CVE-2026-18972 was newly received by cve@rapid7.com as an authenticated identity-spoofing flaw in Velociraptor versions earlier than 0.77.2. The issue allows a low-privileged authenticated attacker to spoof another GUI user via the "Grpc-Metadata-USER" header and potentially take over an administrator account.
A notice reported 15 new vulnerabilities in Rapid7 Velociraptor, including six high-severity issues and one critical issue, affecting versions earlier than 0.77.2. The recommended mitigation was to update to the fixed version in line with the vendor's security bulletins.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.