cvesecurityvulnerability
CVE-2026-18348: Velociraptor NETWORK ACL Bypass via Upload VQL Plugins
Incorrect authorization (CWE-863, CVSS 4.1) in Velociraptor's upload_azure, upload_sftp, and upload_smb VQL plugins lets an analyst-role user bypass the NETWORK ACL for reconnaissance and data exfiltration. Fixed in 0.77.2.