Security Advisory

CVE-2026-18639

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 15:05:42
Last updated 2026-08-11 17:14:12
Assigner rapid7
CVSS score 7.3
State PUBLISHED

Description

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.