Security Advisory

CVE-2026-18972

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 12:30:52
Last updated 2026-08-11 13:51:00
Assigner rapid7
CVSS score 9.6
State PUBLISHED

Description

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.