SB2025101041 - Incorrect permissions in Velociraptor



SB2025101041 - Incorrect permissions in Velociraptor

Published: October 10, 2025

Security Bulletin ID SB2025101041
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Incorrect default permissions (CVE-ID: CVE-2025-6264)

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to the Admin.Client.UpdateClientConfig artifact does not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions to collect it from endpoints and update the configuration. A remote user with COLLECT_CLIENT permissions can execute arbitrary code on the affected endpoints. 


Remediation

Install update from vendor's website.