CVE-2026-18639
EUVD-2026-5618711.08.2026, 16:17
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| rapid7 | velociraptor | 𝑥 < 0.77.2 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure