← Retour à la recherche de CVE

CVE-2026-18639

Description

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the -email_verified- claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.

CVSS 7.3EPSS 0%Risque 0.73
Voir la source
Publication
2026-08-11 16:17:30
Dernière modification
2026-08-11 18:17:21
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N