CVE-2026-18972 UNKNOWN

CVE-2026-18972

Published: 2026-08-11

Description

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…