CVE-2026-15371
8.1Rapid7 · Velociraptor
Rapid7 Velociraptor contains a vulnerability in its web GUI related to improper URL encoding handling, which could allow for unauthorized actions or information disclosure.
Executive summary
A vulnerability in the Rapid7 Velociraptor web GUI allows authenticated high-privileged users to trigger improper handling of URL encoding, posing a significant risk to system integrity.
Vulnerability
The application improperly handles hex encoding within the web GUI when specifying custom column types, which may lead to security bypasses. This vulnerability requires a user with high privileges to initiate the request, making it an authenticated flaw.
Business impact
The CVSS score of 8.1 reflects a high severity rating due to the potential for significant impact on system confidentiality and integrity. Successful exploitation could allow an attacker to manipulate system data or gain elevated control over the Velociraptor deployment, potentially leading to unauthorized access to sensitive endpoint forensic data.
Remediation
Immediate Action: Update Rapid7 Velociraptor to version 0.77.2 or later immediately to incorporate the necessary security fixes.
Proactive Monitoring: Monitor system access logs for unusual administrative activity or unexpected modifications to table configurations within the Velociraptor GUI.
Compensating Controls: Restrict access to the Velociraptor web interface to a limited set of trusted administrative IP addresses to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical nature of forensic platforms like Velociraptor, organizations must prioritize this update. Ensure that all instances are patched to version 0.77.2 or later to prevent potential exploitation of the GUI by malicious actors.