CVE-2026-18639 | Rapid7 Velociraptor up to 0.77.1 OIDC Authentication email/email_verified improper authentication

SecurityVulns

A vulnerability was found in Rapid7 Velociraptor up to 0.77.1. It has been classified as very critical. Affected by this issue is some unknown functionality of the component OIDC Authentication Handler. The manipulation of the argument email/email_verified leads to improper authentication.

This vulnerability is traded as CVE-2026-18639. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More