CVE-2026-18972: Velociraptor authenticated identity-spoofing vulnerability
Published Aug 11, 2026
·Updated
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
Affected Software
1 affected component
Velociraptor Velociraptor
Event History
Aug 11, 2026
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18972?
The severity of CVE-2026-18972 is rated as critical with a score of 9.6.
2
How do I fix CVE-2026-18972?
To fix CVE-2026-18972, update to the latest version of Velociraptor that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-18972?
CVE-2026-18972 is an authenticated identity-spoofing vulnerability that allows attackers to impersonate other users.
4
Who is affected by CVE-2026-18972?
CVE-2026-18972 affects users of Velociraptor who utilize the GUI and have low privileges.
5
What can happen if CVE-2026-18972 is exploited?
Exploitation of CVE-2026-18972 can lead to account takeover from a low-privileged user to an administrator.