Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hunt bypassing any ACL checks that would normally be applied. This flaw can then be escalated to allow the "investigator" user to run arbitrary VQL statements as an administrator user on the Velociraptor server.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-19072 represents a critical privilege escalation vulnerability in Velociraptor where an internal field ('compiled_collector_args') containing pre-compiled VQL statements can be directly manipulated through user API calls. This bypasses the access control checks that normally govern VQL execution, allowing users with minimal investigator privileges to execute arbitrary VQL code they wouldn't otherwise be authorized to run. The vulnerability is particularly severe because it affects hunt operations—the mechanism used to deploy forensic collection across multiple endpoints—meaning a single compromised or malicious investigator account could potentially compromise data collection integrity across an entire infrastructure.
While MITRE ATT&CK techniques are not formally mapped to this CVE, practitioners using Casky.ai would recognize this as a defense evasion and privilege escalation pattern. The attack chain involves API manipulation (T1566 adjacent) combined with authorization bypass mechanisms. Although Casky's current security skills library shows zero direct matches for this specific vulnerability, practitioners analyzing suspicious hunt creation activities would look for behavioral indicators: unusual API calls modifying internal fields, hunts with VQL statements inconsistent with user role permissions, or rapid successive hunt creation by investigator-level accounts. Security teams should implement API request logging and monitoring to detect attempts to set internal Velociraptor fields, correlating with user role capabilities and VQL complexity analysis.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-19072. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation