Improper Access Control in Graylog Log Management Platform
CVE-2026-55425
5MEDIUM
What is CVE-2026-55425?
Graylog, an open-source log management platform, has a vulnerability in the System Catalog entity titles endpoint from versions 7.1.0 to 7.1.4 and 7.2.0-alpha.2. This flaw allows authenticated users to access composite display fields without proper validation, potentially exposing sensitive data such as password hashes from readable user records. Ordinary users can only see their own details, while administrators can obtain data across all user records. This issue has been resolved in versions 7.1.4 and 7.2.0-alpha.2.
Affected Version(s)
graylog2-server >= 7.1.0, < 7.1.4 < 7.1.0, 7.1.4
graylog2-server >= 7.2.0-alpha.1, < 7.2.0-alpha.2 < 7.2.0-alpha.1, 7.2.0-alpha.2
