A vulnerability has been found in Rapid7 Velociraptor up to 0.77.1 and classified as critical. The impacted element is an unknown function of the component Collection Scheduling. Performing a manipulation results in improper privilege management.

This vulnerability was named CVE-2026-64954. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.