CVE-2026-18639: Velociraptor OIDC Authenticator susceptible to email spoofing
Published on 2026-07-31
Vulnogram
CVSS · HIGH · 7.3 ⁄10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Scoring scenario:
GENERAL
attackVector:
NETWORK
attackComplexity:
LOW
privilegesRequired:
LOW
userInteraction:
REQUIRED
scope:
UNCHANGED
confidentialityImpact:
HIGH
integrityImpact:
HIGH
availabilityImpact:
NONE
Description
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email.
This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
Problem
CWE-290: Authentication Bypass by Spoofing
Required configuration for exposure
Velociraptor must be configured to use an IdP which does not verify a user's email and allows the user to set their email. Examples include Azure IdP and Keycloak in self enrollment mode.
Workarounds
You can change the claim that Velociraptor uses as the username using the Configuration File . Set the username using a more permanent claim for example with Azure the "upn" or "oid" can not be chosen by the user.
| Product | Affected |
|---|---|
| Rapid7 Velociraptor on
Linux
source repo Default status is unaffected |
before 0.77.2 |
Credits
- Leonardo Souza (anauaque)