Permission Leak in Graylog2 Server Affects Event Definition Cloning
CVE-2026-65011
5.3MEDIUM
What is CVE-2026-65011?
The Graylog2 Server has a flaw that lacks a proper per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint. This security gap enables authenticated users, even those with low privileges, to clone any event definition. As a result, they can access sensitive information such as private event definitions, detection queries, aggregation thresholds, grouping fields, schedules, and notification settings, thereby posing a risk to the confidentiality and integrity of the organization's data.
Affected Version(s)
graylog2-server 0 <= 7.1.5
graylog2-server 0 <= 7.0.10
graylog2-server 46a2eeba4cdbc1408ff4cbf7b466853a8acfb38d
