An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
http://docs.velociraptor.app/announcements/advisories/cve-2026-18972/