Graylog 是一个免费且开源的日志管理平台。在 6.2.0 至 6.3.12、7.0.7 和 7.1.2 版本中, 端点(由 中的 实现)在解析 所选令牌之前,会先针对攻击者控制的 路径参数检查 权限。一个经过身份验证的用户可以提供一个已授权的 ,而 或 可能解析出属于其他用户(包括服务账户或管理员)的令牌;随后 会删除该令牌,且不会检查 。此问题不会泄露令牌内容,但不授权的删除操作会导致完整性影响,并可能扰乱基于访问令牌的集成。该问题已在 6.3.12、7.0.7 和 7.1.2 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Graylog2 | graylog2-server | >= 6.2.0, < 6.3.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55841 | 7.5 HIGH | Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from |
| CVE-2026-55425 | 5.0 MEDIUM | Graylog: System Catalog titles endpoint can be used to retrieve values of protected databa |
No comments yet