Impersonation Risk in Velociraptor Due to Insecure Email Claim Handling
CVE-2026-18639
7.3HIGH
What is CVE-2026-18639?
Velociraptor's configuration to use an OIDC IdP for authentication poses a significant risk, as it relies on the email claim for username identification. Some Identity Providers (IdPs) permit users to modify their email claims without proper verification, and lack the 'email_verified' claim. This deficiency can lead to unauthorized users impersonating others by simply altering their email address within the IdP, thus allowing potential account takeover incidents of unsuspecting users.
Affected Version(s)
Velociraptor 0 < 0.77.2
