← Volver al buscador de CVEs

CVE-2026-18639

Descripción

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the -email_verified- claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.

CVSS 7.3EPSS 0%Riesgo 0.73
Ver fuente
Publicación
2026-08-11 16:17:30
Última modificación
2026-08-11 18:17:21
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N