Impact
An attacker who authenticates to a Velociraptor instance can impersonate another GUI user by including a custom "Grpc-Metadata-USER" header in their request. This flaw allows a low‑privilege user to assume the identity of a higher‑privilege account and potentially gain administrative control. The core weakness is trust of an injected identity header, mapping to CWE‑290.
Affected Systems
Rapid7 Velociraptor is affected. The advisory lists all Velociraptor releases under the Rapid7:Velociraptor CNA entry, but no specific minor or patch versions are identified as vulnerable. The CPE string indicates all Velociraptor deployments are impacted unless a future patch removes the vulnerable header handling.
Risk and Exploitability
The CVSS score of 9.6 signals a severe vulnerability. The EPSS score of 6% indicates a moderate probability of exploitation; combined with the authentication requirement and lack of a blocking mechanism, the threat likelihood is high. The vulnerability is not present in the CISA KEV catalog at this time, but its high severity warrants immediate attention, especially in environments where users possess elevated privileges. The likely attack vector is a legitimate authenticated session exploiting the unchecked "Grpc-Metadata-USER" header sent by an attacker to the GUI server.
OpenCVE Enrichment