CVE-2026-19584

CVE & Vulnerabilities · September 13, 2026

CVE & Vulnerabilities·nvd.nist.gov

CVE-2026-19584 affects Velociraptor, the open-source digital forensics and incident-response tool, through its default daily notebook-backup feature. A user with notebook-editing rights can embed a malicious VQL query in a notebook, and restoring that backup later runs the query without any permission check, letting it execute with elevated access. The bug highlights the risk of automated backup-restore paths bypassing a tool's normal ACL enforcement.

// source: nvd.nist.gov ↗

Back to Blog