Privilege Escalation Vulnerability in Graylog Log Management Platform
CVE-2025-53106
What is CVE-2025-53106?
In Graylog versions 6.2.0 to 6.2.3 and 6.3.0-alpha.1 to 6.3.0-rc.1, users can exploit a vulnerability that allows for elevated privileges through unauthorized API token creation. An attacker with access to a Graylog user account can send specifically crafted requests to the REST API, bypassing security checks and gaining unauthorized rights. This vulnerability has been addressed in versions 6.2.4 and 6.3.0-rc.2. To mitigate this risk before upgrading, it is recommended to disable the personal access token feature in the system settings.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
graylog2-server >= 6.2.0, < 6.2.4 < 6.2.0, 6.2.4
graylog2-server >= 6.3.0-alpha.1, < 6.3.0-rc.2 < 6.3.0-alpha.1, 6.3.0-rc.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
