Mismanaged Syslog Fields in Graylog by Graylog2 Technologies
CVE-2026-55841
What is CVE-2026-55841?
The Graylog system, known for its log management capabilities, has a significant vulnerability in its syslog parser that permits unauthenticated network actors to manipulate security-log fields. By exploiting mismanagement of quoted values in syslog messages, an attacker can potentially overwrite essential log data, or completely evade logging mechanisms. This imperfection may lead to obscured malicious activities, posing a serious threat to system integrity and operational security. The issue has been addressed in specific versions of Graylog Server and Graylog Forwarder, highlighting the importance of regular updates to safeguard against such vulnerabilities.
Affected Version(s)
graylog2-server < 6.3.12 < 6.3.12
graylog2-server >= 7.0.0-alpha.1, < 7.0.7 < 7.0.0-alpha.1, 7.0.7
graylog2-server >= 7.1.0-alpha.1, < 7.1.2 < 7.1.0-alpha.1, 7.1.2
