Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55841— Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message

Quick assessment

Affected
Graylog2 graylog2-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Graylog 是一个免费且开源的日志管理平台。在 Graylog Server 6.3.12、7.0.7 和 7.1.2 之前,以及 Graylog Forwarder 7.3 之前的版本中,位于 和 中的 FortiGate 键值(key-value)syslog 解析器在处理引号内类字段文本时存在缺陷。 使用了 和 ,而 会调用 FortiGateSyslogEvent 解析器;经过精心构造的包含等号 或反斜杠转义引号的值,可能导致嵌入的键(如 、 、 、 、 )删除或覆盖原始顶层字段,或者生成无效的日志消息

CVSS 7.5 · High

Possible ATT&CK Techniques 2 AI

T1604 T1070 · Indicator Removal
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55841

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message
Source: CVE Program / CVE List V5
Vulnerability Description
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and graylog2-server/src/main/java/org/graylog2/inputs/codecs/SyslogCodec.java mishandles field-like text inside quoted values. GLFortiGateSyslogEvent.getFields() uses KV_PATTERN and QUOTED_KV_PATTERN, while SyslogCodec.parse() invokes the FortiGateSyslogEvent parser; crafted values containing = or backslash-escaped quotes can cause embedded keys such as srcip, dstip, date, time, and tz to remove or overwrite original top-level fields or produce an invalid message that Graylog discards. An unauthenticated network sender who can submit syslog messages can therefore manipulate security-log fields or evade logging to obscure malicious activity. This issue is fixed in Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对特殊元素的转义处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Graylog2 graylog2-server < 6.3.12 -

II. Public POCs for CVE-2026-55841

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55841

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55841 (7)

Vendor Advisories for CVE-2026-55841 (1)

Same Patch Batch · Graylog2 · 2026-08-28 · 3 CVEs total

CVE-2026-55867 5.3 MEDIUM Graylog token revocation endpoint allows authenticated users to delete other users’ access
CVE-2026-55425 5.0 MEDIUM Graylog: System Catalog titles endpoint can be used to retrieve values of protected databa

IV. Related Vulnerabilities

V. Comments for CVE-2026-55841

No comments yet


Leave a comment