CVE-2026-18639: Velociraptor OIDC Authenticator susceptible to email spoofing
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "emailverified" claim and do not actually verify the email.
This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18639?
The severity of CVE-2026-18639 is high with a score of 7.3.
How does CVE-2026-18639 affect Velociraptor?
CVE-2026-18639 allows email spoofing when using OIDC IdP for authentication, compromising user identity.
What systems are vulnerable to CVE-2026-18639?
Velociraptor configured with OIDC IdP that does not verify the email claim is vulnerable to CVE-2026-18639.
How can I mitigate CVE-2026-18639?
To mitigate CVE-2026-18639, ensure that the OIDC IdP properly verifies the email claim and sets the 'email_verified' claim.
When was CVE-2026-18639 published?
CVE-2026-18639 was published on August 11, 2026.