AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18348

MEDIUM · CVSS 4.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Authenticated users with analyst roles in Oracle's Velociraptor server can exploit a missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins to establish unauthorized outbound network connections. This vulnerability allows for internal network reconnaissance and potential data exfiltration to external endpoints, posing a risk to sensitive information. Organizations using Oracle's Velociraptor should prioritize addressing this issue to mitigate the risk of unauthorized data access and leakage.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18348
Severity
MEDIUM
CVSS
4.1
EPSS
0.25%
Oracle

Original NVD Description

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.