This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
You can change the claim that Velociraptor uses as the username using the Configuration File https://docs.velociraptor.app/docs/deployment/references/#GUI.authenticator.claims.username . Set the username using a more permanent claim for example with Azure the "upn" or "oid" can not be chosen by the user.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover. | |
| Title | Velociraptor OIDC Authenticator susceptible to email spoofing | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-11T15:05:42.703Z
Reserved: 2026-08-03T10:45:09.071Z
Link: CVE-2026-18639
No data.
Status : Received
Published: 2026-08-11T16:17:30.590
Modified: 2026-08-11T16:17:30.590
Link: CVE-2026-18639
No data.
OpenCVE Enrichment
No data.