LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-18639

Published
CVSS7.3
Severityhigh
WeaknessCWE-290
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Description

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-18639

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-18639.