Rapid7CVE-2026-18639
Rapid7 Velociraptor: authentication bypass by spoofing
High7.3CVE-2026-18639 · Published Aug 11, 2026 · updated Aug 28, 2026
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Velociraptor Product | < 0.77.2 | 0.77.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-290
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Rapid7 Velociraptor: null pointer dereference | Medium6.5 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: path traversal | High7.1 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: improper authorization | High7.2 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: authentication bypass | Medium6.8 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: improper permission handling | High8.7 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: denial of service | Medium6.2 | 0.77.2 |