A AegiFlow
MEDIUMCVSS 5.0EPSS 0.3%

CVE-2026-55425

CVE-2026-55425 updated by NVD

Published
2026-08-28
Modified
2026-09-11
EPSS percentile
22%
Sources
github-advisory, nvd

Summary

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java allows an authenticated user to request composite display fields without verifying that every selected field is readable. A user can retrieve protected values, including the password hash on a readable user record; ordinary users are limited to their own permitted records, while administrators can retrieve hashes for all users. This issue is fixed in versions 7.1.4 and 7.2.0-alpha.2.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.graylog2:graylog2-server7.1.4

Remediation: Upgrade to 7.1.4 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.