CVE-2026-8795 | Rapid7 Velociraptor up to 0.76.5 client_info.json Hostname injection
A vulnerability was found in Rapid7 Velociraptor up to 0.76.5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file client_info.json. Executing a manipulation of the argument Hostname can lead to injection.
The identification of this vulnerability is CVE-2026-8795. The attack can only be executed locally. There is no exploit available.
It is recommended to upgrade the affected component.