CVE-2026-18639

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 16:17

Updated : 2026-08-28 21:17


NVD link : CVE-2026-18639

Mitre link : CVE-2026-18639

CVE.ORG link : CVE-2026-18639


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing