CVE-2026-69190
6.3Graylog2 · graylog2-server
Graylog2 server contains an authorization bypass vulnerability in the view update API, allowing authenticated users to escalate their own permissions for saved searches and dashboards.
Executive summary
A vulnerability in the Graylog2 view update API allows authenticated users to hijack ownership of dashboards and saved searches, potentially leading to unauthorized data deletion or access control manipulation.
Vulnerability
This flaw stems from improper authorization checks within the view update API. An attacker with standard edit permissions can manipulate a shareRequest parameter to grant themselves ownership of entities they do not own, effectively bypassing intended access restrictions.
Business impact
The ability for a low-privileged user to assume ownership of critical logging dashboards or saved searches poses a significant risk to operational integrity. An attacker could delete audit-critical records or remove administrative access to sensitive log views, leading to potential data loss and the impairment of security monitoring capabilities. While the CVSS score of 6.3 reflects a moderate risk, the potential for unauthorized administrative actions within a security platform necessitates prompt remediation.
Remediation
Immediate Action: Update the Graylog2 server to version 6.3.14, 7.0.9, or 7.1.4, depending on the current deployment branch.
Proactive Monitoring: Review audit logs for unusual ownership changes on saved searches or dashboards, particularly those initiated by non-administrative user accounts.
Compensating Controls: Restrict access to the API and administrative interfaces to trusted networks, and enforce the principle of least privilege by auditing existing user permissions within the Graylog environment.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Graylog2 should prioritize upgrading to the patched versions specified above to eliminate this authorization vulnerability. Given that this flaw allows for the manipulation of sensitive log management configurations, delaying the update increases the risk of internal sabotage or unauthorized access to critical security data.
More Graylog2 CVEs
History
- Analyst report written
Sources
- https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-m9c2-85gv-8xr5
- https://github.com/Graylog2/graylog2-server/pull/26344
- https://github.com/Graylog2/graylog2-server/commit/9303f395dd29c03abd8885f1c7d1c90f8aae72d4
- https://github.com/Graylog2/graylog2-server/commit/ac1c0b19e3f44c2eed8e95f4d398ba455e30a8f2
- https://github.com/Graylog2/graylog2-server/commit/c87879642537d07760a572ba01b76cb657582608
- https://github.com/Graylog2/graylog2-server/commit/e98c6670d05748a9749ab0646be7f40561734b42
- https://github.com/Graylog2/graylog2-server/releases/tag/6.3.14
- https://github.com/Graylog2/graylog2-server/releases/tag/7.0.9