CRITICAL 9.6 NVD
CVE-2026-18972
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an acco
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
References
This critical severity vulnerability with a CVSS score of 9.6 was published on 2026-08-11 via NVD.
Risk Timeline
CVE Disclosed2026-08-11 · -1 days ago
Remediation Resources
Official Advisory
docs.velociraptor.app/announcements/advisories/cve-2026-18972/
vulnfeed aggregates 9844 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.