CVE-2026-18348
MEDIUM
NVD
CVSS Score
4.1
Severity
MEDIUM
Published
Aug 11, 2026
Vendor
unknown
Description
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.