PT-2026-94066 · Graylog2+1 · Graylog2-Server

·

CVE-2026-92789

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Graylog versions prior to 7.1.5
Description The software validates outbound URLs against an allowlist before making requests but fails to re-validate them after following HTTP redirects. Users with lookup table or event notification permissions can create allowlisted endpoints that redirect to internal services, allowing the server to fetch and return internal responses. This behavior enables a Server-Side Request Forgery (SSRF), where an attacker induces the server to make requests to an unintended location.
Recommendations Update to version 7.1.5 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92789

Affected Products

Graylog2-Server