CVE-2026-18972: Velociraptor authenticated identity-spoofing vulnerability
Published Aug 11, 2026
·Updated
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
Affected Software
1 affected component
Velociraptor Velociraptor
Event History
Aug 11, 2026
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness