docs.velociraptor.app
http://docs.velociraptor.app/announcements/advisories/cve-2026-18640 CVE-2026-18640
HIGH
Velociraptor directory traversal via the NewNotebook API
Record summary
CVE-2026-18640 has a selected CVSS score of 7.1 (high).
Description
The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
VelociraptorBrowse Rapid7 / VelociraptorDefault status: unaffected | CVE List | Before 0.77.2 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-18640