Mismanaged Syslog Fields in Graylog by Graylog2 Technologies
CVE-2026-55841

7.5HIGH

Key Information:

Vendor

Graylog2

Vendor
CVE Published:
28 August 2026

What is CVE-2026-55841?

The Graylog system, known for its log management capabilities, has a significant vulnerability in its syslog parser that permits unauthenticated network actors to manipulate security-log fields. By exploiting mismanagement of quoted values in syslog messages, an attacker can potentially overwrite essential log data, or completely evade logging mechanisms. This imperfection may lead to obscured malicious activities, posing a serious threat to system integrity and operational security. The issue has been addressed in specific versions of Graylog Server and Graylog Forwarder, highlighting the importance of regular updates to safeguard against such vulnerabilities.

Affected Version(s)

graylog2-server < 6.3.12 < 6.3.12

graylog2-server >= 7.0.0-alpha.1, < 7.0.7 < 7.0.0-alpha.1, 7.0.7

graylog2-server >= 7.1.0-alpha.1, < 7.1.2 < 7.1.0-alpha.1, 7.1.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.