Improper Access Control in Graylog Log Management Platform
CVE-2026-55425

5MEDIUM

Key Information:

Vendor

Graylog2

Vendor
CVE Published:
28 August 2026

What is CVE-2026-55425?

Graylog, an open-source log management platform, has a vulnerability in the System Catalog entity titles endpoint from versions 7.1.0 to 7.1.4 and 7.2.0-alpha.2. This flaw allows authenticated users to access composite display fields without proper validation, potentially exposing sensitive data such as password hashes from readable user records. Ordinary users can only see their own details, while administrators can obtain data across all user records. This issue has been resolved in versions 7.1.4 and 7.2.0-alpha.2.

Affected Version(s)

graylog2-server >= 7.1.0, < 7.1.4 < 7.1.0, 7.1.4

graylog2-server >= 7.2.0-alpha.1, < 7.2.0-alpha.2 < 7.2.0-alpha.1, 7.2.0-alpha.2

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.