---
id: CVE-2026-18972
title: >-
  An authenticated attacker can spoof another GUI user's identity by sending
  their request with the custom header \"Grpc-Metadata-USER\"
summary: >-
  An authenticated attacker can spoof another GUI user's identity by sending
  their request with the custom header \"Grpc-Metadata-USER\". This can lead to
  an account takeover attack from a user with low privileges to administrator.
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-290
published: '2026-08-11'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18972'
references:
  - url: 'http://docs.velociraptor.app/announcements/advisories/cve-2026-18972/'
    label: cve@rapid7.com
tags:
  - nvd
epss: 0.06059
epssPercentile: 0.93069
ingestedAt: '2026-08-29T19:41:14.016Z'
---

## Overview

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
