When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email.
This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 16:17
Updated : 2026-08-28 21:17
NVD link : CVE-2026-18639
Mitre link : CVE-2026-18639
CVE.ORG link : CVE-2026-18639
JSON object : View
Products Affected
No product.
CWE
CWE-290
Authentication Bypass by Spoofing
