Description
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
If you have a proxy in front of the Velociraptor GUI server, you can block the \"Grpc-Metadata-USER\" header.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 11 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator. | |
| Title | Velociraptor authenticated identity-spoofing vulnerability | |
| First Time appeared |
Rapid7
Rapid7 velociraptor |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rapid7
Rapid7 velociraptor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-11T12:30:52.574Z
Reserved: 2026-08-05T16:09:39.892Z
Link: CVE-2026-18972
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses