CVE-2026-18638
EUVD-2026-5618511.08.2026, 16:17
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| rapid7 | velociraptor | 𝑥 < 0.77.2 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure