Beveiligingsadvies

CVE-2026-18972

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-11 12:30:52
Laatst bijgewerkt 2026-08-11 13:51:00
Toegewezen door rapid7
CVSS-score 9.6
Status PUBLISHED

Beschrijving

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.