CVE-2026-18972Patch

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-11); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-08-11: 3Mentions · 2026-08-12: 2Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-12: 2Technical Details · 2026-08-11: 3Technical Details · 2026-08-12: 208-1108-12
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-113
Disclosure2Patch1
2026-08-122
Patch2
Full discourse5 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Authentication bypass and other vulnerabilities in #Rapid7 #Velociraptor. CVE-2026-18972 CVSS: 9.6. Authenticated attackers can spoof user IDs, leading to account takeover! This and other vulnerabilities in: https://docs.velociraptor.app/announcements/advisories/ #Patch #Patch #Patch

    Post summary

    The post warns of a critical authentication bypass flaw (CVE‑2026‑18972) in Rapid7 Velociraptor with a CVSS of 9.6, highlights how attackers can spoof user IDs to take over accounts, and directs readers to vendor advisories for patching.

    01000323
    7.2K followersView on X
  • Sami Laiho@samilaiho
    Patch

    Velociraptor authenticated identity-spoofing vulnerability URL: https://docs.velociraptor.app/announcements/advisories/cve-2026-18972/ Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6

    Post summary

    Velociraptor released an official fix for the critical authenticated identity‑spoofing vulnerability CVE‑2026‑18972 (CVSS 9.6), but no PoC, exploit code, or evidence of active exploitation was reported.

    01000680
    30.6K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Velociraptor GUI User Spoofing Enables Privilege Escalation to Admin (CVE-2026-18972) Velociraptor, the open-source DFIR and endpoint-hunting platform, has an authentication bypass in its GUI. An authenticated attacker can impersonate any other GUI user simply by adding a custom Grpc-Metadata-USER header to their request. This lets a low-privileged user take over accounts, including administrator. Admin on a Velociraptor server means control over fleet-wide endpoint collection and querying, so the impact goes well beyond the console itself. It requires an existing low-privilege account, and the fix is already available. CVSS 9.6. 👉Upgrade Velociraptor to 0.77.2 per the Rapid7 advisory.

    Post summary

    A severe authentication bypass (CVE-2026-18972) in Velociraptor’s GUI lets low‑privileged users impersonate any other user via a custom header, enabling admin‑level access; the vulnerability is mitigated by upgrading to v0.77.2 as per the Rapid7 advisory.

    0000068
    285 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-18972 An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account ta… https://www.cve.org/CVERecord?id=CVE-2026-18972 ----- Traducción: CVE-2026-18972 Un … http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-18972, detailing how an authenticated attacker can spoof a GUI user's identity using a custom header, but it lacks evidence of exploits, patches, or active use.

    0000034
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18972 An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account ta… https://www.cve.org/CVERecord?id=CVE-2026-18972

    Post summary

    The entry outlines CVE-2026-18972, indicating an authenticated attacker can spoof another GUI user by manipulating the custom header "Grpc-Metadata-USER", but provides no PoC, exploit code, active exploitation evidence, or patch information.

    00000996
    57.9K followersView on X

Explore more