Beveiligingsadvies

CVE-2026-18639

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-11 15:05:42
Laatst bijgewerkt 2026-08-11 17:14:12
Toegewezen door rapid7
CVSS-score 7.3
Status PUBLISHED

Beschrijving

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.