GHSA-q79r-r9xg-r863: Medium severity maven/org.graylog2:graylog2-server vulnerability

Published Aug 28, 2026
·
Updated

Impact

A vulnerability was found in Graylog's API endpoint for retrieving system catalog entity titles. Authenticated users could retrieve database fields of supported entities by sending a custom API request. These fields can include e.g. the password hash of a user (but not the password itself), which should not be returned through the API, regardless of the endpoint. Permission checks do still apply, so users can retrieve their own password hash, but not those of other users. The admin user (or any user with an admin role) can retrieve password hashes of all users.

Patches

This issue has been patched in Graylog 7.1.4. In this version, an allow list will be used to check if protected fields are being accessed, refusing those requests. Affected users should upgrade to 7.1.4 or above to remediate the vulnerability.

Workarounds

There is no known workaround. Upgrading to a patched version is recommended.

Credits

Thanks to Evelynkaz for reporting.

Affected Software

1 affected componentFixes available
maven/org.graylog2:graylog2-server>=7.1.0<=7.1.3
7.1.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.graylog2:graylog2-server to a version that resolves this vulnerability.

    Fixed in 7.1.4
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 7.1.4

Event History

Aug 28, 2026
Advisory Published
via GitHub·06:09 PM
Data Sourced
via GitHub·06:09 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue, and what access do they need?

An attacker must be authenticated to Graylog and able to send a custom request to the API endpoint that retrieves system catalog entity titles. Permission checks still apply, so non-administrative users can retrieve fields only for entities they are permitted to access.

2

What sensitive information may be exposed?

Supported entity database fields may be returned through the API, including a user's password hash. Passwords themselves are not exposed through this issue.

3

Are administrator accounts at greater risk?

Yes. The admin user and users with an admin role can retrieve password hashes for all users, while other users cannot retrieve password hashes belonging to other users.

4

What version fixes the issue, and is there a workaround?

Graylog 7.1.4 adds an allow list that rejects requests for protected fields. There is no known workaround; upgrade to version 7.1.4 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203