SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAwaiting Analysis

CVE-2026-19200

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues.

HIGH 8.9EPSS 0.23%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.

CVSS 3.1
8.9 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
EPSS
0.23% probability · 14th percentile
CISA KEV
Not listed
Weakness
CWE-94, CWE-862
Source
cve@rapid7.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.