This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
You can change the claim that Velociraptor uses as the username using the Configuration File https://docs.velociraptor.app/docs/deployment/references/#GUI.authenticator.claims.username . Set the username using a more permanent claim for example with Azure the "upn" or "oid" can not be chosen by the user.
Tue, 11 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover. | |
| Title | Velociraptor OIDC Authenticator susceptible to email spoofing | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-11T17:14:12.967Z
Reserved: 2026-08-03T10:45:09.071Z
Link: CVE-2026-18639
Updated: 2026-08-11T17:14:05.603Z
Status : Received
Published: 2026-08-11T16:17:30.590
Modified: 2026-08-11T18:17:21.650
Link: CVE-2026-18639
No data.
OpenCVE Enrichment
No data.