PT-2026-83241 · Graylog · Graylog
CVE-2026-55425
·
Published
2026-08-28
·
Updated
2026-08-28
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Graylog versions 7.1.0 through 7.1.3
Graylog versions 7.2.0-alpha.0 through 7.2.0-alpha.1
Description
An issue exists in the System Catalog entity titles endpoint within
graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java that allows an authenticated user to request composite display fields without proper verification of field readability. This allows users to retrieve protected values, such as password hashes, from readable user records. While ordinary users are limited to their own permitted records, users with administrator roles can retrieve password hashes for all users.Recommendations
Update Graylog to version 7.1.4 or later.
Update Graylog to version 7.2.0-alpha.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Graylog