Ghostwire

CVE-2026-19200: The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an...

HIGH CVSS 8.9 Exploit Available

Published: August 24, 2026 | Last Modified: August 24, 2026

Description

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References