PT-2026-83347 · Graylog · Graylog Forwarder+1
CVE-2026-55841
·
Published
2026-08-28
·
Updated
2026-09-01
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Graylog Server versions prior to 6.3.12
Graylog Server versions prior to 7.0.7
Graylog Server versions prior to 7.1.2
Graylog Forwarder versions prior to 7.3
Description
The FortiGate key-value syslog parser mishandles field-like text inside quoted values. Specifically, the
getFields() function in GLFortiGateSyslogEvent.java uses KV PATTERN and QUOTED KV PATTERN, while the parse() function in SyslogCodec.java invokes the FortiGateSyslogEvent parser. An unauthenticated network sender can submit crafted syslog messages containing = or backslash-escaped quotes to manipulate embedded keys such as srcip, dstip, date, time, and tz. This allows the attacker to remove or overwrite original top-level fields or produce invalid messages that the system discards, enabling log evasion to obscure malicious activity.Recommendations
Update Graylog Server to version 6.3.12 or later.
Update Graylog Server to version 7.0.7 or later.
Update Graylog Server to version 7.1.2 or later.
Update Graylog Forwarder to version 7.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Graylog Forwarder
Graylog Server