CVE-2026-55425: Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fields

Published Aug 28, 2026
·
Updated

Impact

A vulnerability was found in Graylog's API endpoint for retrieving system catalog entity titles. Authenticated users could retrieve database fields of supported entities by sending a custom API request. These fields can include e.g. the password hash of a user (but not the password itself), which should not be returned through the API, regardless of the endpoint. Permission checks do still apply, so users can retrieve their own password hash, but not those of other users. The admin user (or any user with an admin role) can retrieve password hashes of all users.

Patches

This issue has been patched in Graylog 7.1.4. In this version, an allow list will be used to check if protected fields are being accessed, refusing those requests. Affected users should upgrade to 7.1.4 or above to remediate the vulnerability.

Workarounds

There is no known workaround. Upgrading to a patched version is recommended.

Credits

Thanks to Evelynkaz for reporting.

Other sources

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java allows an authenticated user to request composite display fields without verifying that every selected field is readable. A user can retrieve protected values, including the password hash on a readable user record; ordinary users are limited to their own permitted records, while administrators can retrieve hashes for all users. This issue is fixed in versions 7.1.4 and 7.2.0-alpha.2.

MITRE

Affected Software

1 affected componentFixes available
maven/org.graylog2:graylog2-server>=7.1.0<=7.1.3
7.1.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.graylog2:graylog2-server to a version that resolves this vulnerability.

    Fixed in 7.1.4
  2. Upgrade

    Upgrade Graylog to a version that resolves this vulnerability.

    Fixed in 7.1.4
  3. Upgrade

    Upgrade Graylog to a version that resolves this vulnerability.

    Fixed in 7.2.0-alpha.2

Event History

Aug 28, 2026
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:09 PM
Data Sourced
via GitHub·06:09 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What level of access is required to retrieve protected entity fields?

An attacker must be authenticated. Permission checks still apply: non-admin users can retrieve their own password hash but not other users' hashes, while administrators or users with an admin role can retrieve password hashes for all users.

2

What data may be exposed?

Supported entity database fields may be returned through a custom API request. This can include password hashes, but not users' plaintext passwords.

3

How is the issue remediated?

Upgrade to Graylog 7.1.4 or later. The patched version uses an allow list to reject requests for protected fields.

4

Is there a mitigation if an upgrade cannot be performed immediately?

No known workaround is available. Upgrading to a patched version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203