CVE-2026-18972

Summary

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header "Grpc-Metadata-USER". This can lead to an account takeover attack from a user with low privileges to administrator.

Affected Software

VendorProductVersion RangeStatus
Rapid7Velociraptor0 < 0.77.2affected

Weaknesses

  • CWE-290: CWE-290 Authentication bypass by spoofing

Workarounds

If you have a proxy in front of the Velociraptor GUI server, you can block the &#34;Grpc-Metadata-USER&#34; header.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References