Sami Laiho[verified]@samilaihoPatch
Velociraptor released an official fix for the critical authenticated identity‑spoofing vulnerability CVE‑2026‑18972 (CVSS 9.6), but no PoC, exploit code, or evidence of active exploitation was reported.
Upwind Security MDR[verified]@UpwindMDRPatch
A severe authentication bypass (CVE-2026-18972) in Velociraptor’s GUI lets low‑privileged users impersonate any other user via a custom header, enabling admin‑level access; the vulnerability is mitigated by upgrading to v0.77.2 as per the Rapid7 advisory.
CCB Alert@CCBalertPatch
The post warns of a critical authentication bypass flaw (CVE‑2026‑18972) in Rapid7 Velociraptor with a CVSS of 9.6, highlights how attackers can spoof user IDs to take over accounts, and directs readers to vendor advisories for patching.
Infoflowcloud@infoflowcloudDisclosure
The message announces CVE-2026-18972, detailing how an authenticated attacker can spoof a GUI user's identity using a custom header, but it lacks evidence of exploits, patches, or active use.
CVE@CVEnewDisclosure
The entry outlines CVE-2026-18972, indicating an authenticated attacker can spoof another GUI user by manipulating the custom header "Grpc-Metadata-USER", but provides no PoC, exploit code, active exploitation evidence, or patch information.