CWE
79
EPSS
0.033%
Advisory Published
CVE Published
Updated

CVE-2025-46827: Graylog Allows Session Takeover via Insufficient HTML Sanitization

First published: Wed May 07 2025(Updated: )

### Impact It is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, the attacker needs a user account with permissions to create event definitions, while the user must have permissions to view alerts. Additionally, an active Input must be present on the Graylog server that is capable of receiving form data (e.g. a HTTP input, TCP raw or syslog etc). ### Patches ### Workarounds None, as long as the relatively rare prerequisites are met. Analysis provided by Fabian Yamaguchi - Whirly Labs (Pty) Ltd

Credit: security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
maven/org.graylog2:graylog2-server>=6.1.0<=6.1.9
6.1.10
maven/org.graylog2:graylog2-server<=6.0.13
6.0.14

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2025-46827?

    CVE-2025-46827 has been classified with a high severity due to its potential for session cookie theft.

  • How do I fix CVE-2025-46827?

    To resolve CVE-2025-46827, update the graylog2-server package to version 6.1.10 or 6.0.14.

  • What versions are affected by CVE-2025-46827?

    CVE-2025-46827 affects graylog2-server versions from 6.1.0 to 6.1.9 and up to 6.0.13.

  • Who can exploit CVE-2025-46827?

    An attacker with a user account that has permissions to create event definitions can exploit CVE-2025-46827.

  • What is the impact of CVE-2025-46827?

    The impact of CVE-2025-46827 allows attackers to obtain user session cookies through a crafted HTML form.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203