CVE-2026-18972
CRITICAL
NVD
CVSS Score
9.6
Severity
CRITICAL
Published
Aug 11, 2026
Vendor
unknown
Description
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.