boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-18652

Rapid7 Velociraptor — Velociraptor STACK Type Download Path Bypasses Denied Prefix Check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0027   18.0     —
AFFECTED
  Product       Versions     Fixed
  Velociraptor  unspecified  —
TIMELINE
  Aug 3   Reserved by rapid7
  Aug 12  Published (CNA: rapid7)
  Aug 24  RESCORED — CVE-2026-18652 (Rapid7 Velociraptor). CVSS 4.9 → 6.5 (NVD).
CWE-862 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis

Description

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes. In particular, a user with read access to the root org can access result sets from child orgs.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 3, 2026ReservedReserved by rapid7
August 12, 2026PublishedPublished (CNA: rapid7)
August 24, 2026RESCOREDRESCORED — CVE-2026-18652 (Rapid7 Velociraptor). CVSS 4.9 → 6.5 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Rapid7Velociraptor———

Weaknesses

CWE-862

References (1)

Related

Authoritative record: CVE-2026-18652 at cve.org

Vendors: rapid7

Weaknesses: CWE-862

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-18652 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.