CVE Explorer
CVE-2026-5329
Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring message with a malicious queue name. The server handler that receives client monitoring messages does not sufficiently validate the queue name supplied by the client, allowing a rogue client to write ar
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Linux"],"product":"Velociraptor","repo":"https://github.com/Velocidex/velociraptor","vendor":"Rapid7","versions":[{"lessThanOrEqual":"0.76.3","status":"affected","version":"0","versionType":"semver"},{"lessThanOrEqual":"0.75.6","status":"affected","version":"0","versionType":"semver"},{"lessThanOrEqual":"0.74.6","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a015dc9bd7e52778b7d974740f70dada14dc80d544a2da02203ed7e02e128475 · sha256:8c2eef31b5859011… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a015dc9bd7e52778b7d974740f70dada14dc80d544a2da02203ed7e02e128475 · sha256:8c2eef31b5859011… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20 Improper input validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a015dc9bd7e52778b7d974740f70dada14dc80d544a2da02203ed7e02e128475 · sha256:8c2eef31b5859011… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://docs.velociraptor.app/announcements/advisories/cve-2026-5329/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a015dc9bd7e52778b7d974740f70dada14dc80d544a2da02203ed7e02e128475 · sha256:8c2eef31b5859011… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.