What is CVE-2026-18972?
CVE-2026-18972 is a vulnerability that allows an authenticated attacker to spoof another GUI user's identity by sending requests with a custom `Grpc-Metadata-USER` header. This can lead to a full account takeover, escalating privileges from a low-privileged user to an administrator. Affected GUI modules should be patched immediately.
Azərbaycanca: CVE-2026-18972 autentifikasiya olunmuş təcavüzkara xüsusi HTTP başlığı (`Grpc-Metadata-USER`) vasitəsilə GUI-də başqa istifadəçinin kimliyini ələ keçirməyə imkan verən boşluqdur. Bu, aşağı səlahiyyətli istifadəçinin administrator hesabını ələ keçirməsinə səbəb ola bilər. Təsirlənmiş sistemin GUI modulu yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
How can an attacker exploiting CVE-2026-18972 take over an administrator account?
An authenticated attacker can spoof another user's identity in the GUI, including an administrator's, by sending requests with a custom `Grpc-Metadata-USER` HTTP header.
Which system component must be updated to mitigate CVE-2026-18972?
The affected system's GUI module should be patched immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.