CVE-2026-18972 | Rapid7 Velociraptor up to 0.77.1 Grpc-Metadata-USER privileges management (EUVD-2026-56127)
A vulnerability was found in Rapid7 Velociraptor up to 0.77.1 and classified as very critical. Affected is an unknown function. Such manipulation of the argument Grpc-Metadata-USER leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2026-18972. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More