Loading market data...
← Back to CVE feed

CVE-2026-18639

HIGH CVSS 7.3 View on NVD ↗

Description

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Published: Aug 11, 2026 16:17 UTC Modified: Aug 11, 2026 18:17 UTC