Junglewise Threat Intelligence

CVE-2026-18972: Velociraptor GUI authenticated identity spoofing via Grpc-Metadata-USER header

CVE-2026-18972 · Severity: critical · CVSS 9.6 · Published 2026-08-11

Technologies: Velociraptor.

Executive brief

Velociraptor is a digital forensics and endpoint monitoring platform used by security teams to investigate incidents and collect evidence from computers. An authenticated attacker can hijack another user's identity by forging a custom HTTP header, potentially escalating from a regular user account to administrative privileges and gaining full control of the system.

Technical details

This is an authentication bypass / identity spoofing vulnerability in the Velociraptor GUI. An authenticated attacker can send a specially crafted request with the "Grpc-Metadata-USER" custom header to spoof the identity of another user, including administrators. The vulnerability allows privilege escalation from a low-privileged authenticated user to administrator level. The attack requires the attacker to already have valid authentication credentials and network access to the GUI. Velociraptor has released version 0.77.2 as a patch for this vulnerability.

Affected products

  • Velociraptor Velociraptor before 0.77.2

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Fix available in version 0.77.2

References