No analysis available yet.
Vendor Workaround
If you have a proxy in front of the Velociraptor GUI server, you can block the \"Grpc-Metadata-USER\" header.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator. | |
| Title | Velociraptor authenticated identity-spoofing vulnerability | |
| First Time appeared |
Rapid7
Rapid7 velociraptor |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rapid7
Rapid7 velociraptor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-11T13:51:00.275Z
Reserved: 2026-08-05T16:09:39.892Z
Link: CVE-2026-18972
Updated: 2026-08-11T13:50:56.518Z
Status : Received
Published: 2026-08-11T13:17:56.997
Modified: 2026-08-11T14:17:12.920
Link: CVE-2026-18972
No data.
OpenCVE Enrichment
No data.
-
CWE-290
Authentication Bypass by Spoofing