← Zurück zur CVE-Suche

CVE-2026-18639

Beschreibung

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the -email_verified- claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.

CVSS 7.3EPSS 0%Risiko 0.73
Quelle öffnen
Veröffentlicht
2026-08-11 16:17:30
Zuletzt geändert
2026-08-11 18:17:21
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N