云虫漏洞库

CVE-2026-18636 - The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission. - 漏洞详情

漏洞编号:CVE-2026-18636

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-18636

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-288

发布/更新时间:2026-08-11 / 2026-08-28

漏洞描述

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.

相关链接

相关漏洞

« 返回首页