#cve202618972 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve202618972, aggregated by home.social.
-
CVE-2026-18972 (CRITICAL): Rapid7 Velociraptor <0.77.2 lets low-priv users escalate to admin by spoofing 'Grpc-Metadata-USER' header — full account takeover. No patch yet. Restrict GUI access, monitor requests. https://radar.offseq.com/threat/cve-2026-18972-cwe-290-authentication-bypass-by-spoofing-in-rapid7-velociraptor-72ecf6c68bed741e #OffSeq #Velociraptor #CVE202618972
-
CVE-2026-18972 (CRITICAL): Rapid7 Velociraptor <0.77.2 lets low-priv users escalate to admin by spoofing 'Grpc-Metadata-USER' header — full account takeover. No patch yet. Restrict GUI access, monitor requests. https://radar.offseq.com/threat/cve-2026-18972-cwe-290-authentication-bypass-by-spoofing-in-rapid7-velociraptor-72ecf6c68bed741e #OffSeq #Velociraptor #CVE202618972
-
CVE-2026-18972 (CRITICAL): Rapid7 Velociraptor <0.77.2 lets low-priv users escalate to admin by spoofing 'Grpc-Metadata-USER' header — full account takeover. No patch yet. Restrict GUI access, monitor requests. https://radar.offseq.com/threat/cve-2026-18972-cwe-290-authentication-bypass-by-spoofing-in-rapid7-velociraptor-72ecf6c68bed741e #OffSeq #Velociraptor #CVE202618972