CVE-2026-18972
EUVD-2026-5612711.08.2026, 13:17
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| rapid7 | velociraptor | 𝑥 < 0.77.2 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure