CVEPublished 2026-08-24Modified 2026-08-281 article on news4 live referencesNVD data

CVE-2026-19200

Vulnerability data via NVD (ingested)

CVSS v3.1
8.9
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
EPSS percentile
13
Exploit Prediction Scoring System · top 87% of all CVEs
Description

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.

Timeline
Published 2026-08-24
Modified 2026-08-28

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (2)