PT-2026-96190 · Graylog · Graylog

CVE-2026-69190

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Graylog versions 6.3.0 through 6.3.13 Graylog versions 7.0.x prior to 7.0.9 Graylog versions 7.1.x prior to 7.1.4
Description The view update API for saved searches and dashboards allows a user with edit permissions, who is not the entity owner, to include a shareRequest that grants owner permissions to an arbitrary account. This can enable the selected account to delete the saved search or dashboard or revoke the original owner's access.
Recommendations Update Graylog to version 6.3.14. Update Graylog to version 7.0.9. Update Graylog to version 7.1.4.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69190
GHSA-M9C2-85GV-8XR5

Affected Products

Graylog