PT-2026-83241 · Graylog · Graylog

CVE-2026-55425

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Graylog versions 7.1.0 through 7.1.3 Graylog versions 7.2.0-alpha.0 through 7.2.0-alpha.1
Description An issue exists in the System Catalog entity titles endpoint within graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java that allows an authenticated user to request composite display fields without proper verification of field readability. This allows users to retrieve protected values, such as password hashes, from readable user records. While ordinary users are limited to their own permitted records, users with administrator roles can retrieve password hashes for all users.
Recommendations Update Graylog to version 7.1.4 or later. Update Graylog to version 7.2.0-alpha.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55425
GHSA-Q79R-R9XG-R863

Affected Products

Graylog