AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-18972

CRITICAL · CVSS 9.6 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

An authenticated attacker can exploit a vulnerability in the system by manipulating the "Grpc-Metadata-USER" header to impersonate another GUI user, potentially escalating their privileges from a low-level account to that of an administrator. This critical vulnerability poses a significant risk of account takeover, making it essential for organizations using affected products to prioritize immediate remediation efforts to protect against unauthorized access. Security teams should focus on implementing proper input validation and access controls to mitigate this threat.

CVE
CVE-2026-18972
Severity
CRITICAL
CVSS
9.6
EPSS
0.33%

Original NVD Description

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.