PT-2026-63436 · Graylog2+1 · Graylog2-Server

·

CVE-2026-65011

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Graylog2 Server versions prior to commit 46a2eeb
Description An issue exists where a per-entity permission check is missing in the 'POST /events/definitions/{definitionId}/duplicate' endpoint. This allows authenticated users with the eventdefinitions:create capability to clone any event definition. By duplicating these definitions, attackers can read private information, including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings.
Recommendations Update Graylog2 Server to commit 46a2eeb or a later version. Restrict the use of the eventdefinitions:create capability to trusted users until the update is applied.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65011

Affected Products

Graylog2-Server