CVE-2026-18972
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedAn authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator. Source description excerpt; complete tracked detail loads below.
Evidence: Source reported · Source: CVE record · Source last published: 2026-08-11 12:30 UTC · Source last updated: 2026-08-11 12:48 UTC · Tracker data as of: 2026-08-11 13:56 UTC
What is affected
ReportedRapid7 — Velociraptor. Product-level identification only; no affected-version conclusion is available from this field.
Evidence: Source reported · Source: CVE record · Source last published: 2026-08-11 12:30 UTC · Source last updated: 2026-08-11 12:48 UTC · Tracker data as of: 2026-08-11 13:56 UTC
Urgency and basis
ReportedTrack* · 219.5
Evidence: Tracker computed · Tracker decision tier from the evidence detailed below · Source last updated: 2026-08-11 12:48 UTC · Tracker data as of: 2026-08-11 13:56 UTC
Exploitation evidence
Not reportedNot reported by tracked sources.
What to do
Not reportedNot reported by tracked sources.
Evidence detail
Loading the full tracker evidence record…