CVE 7.1 HIGH

Improper Access Control (IDOR) vulnerability in Graylog Web Interface_CVE-2026-1436

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without proper authorization checks. Exploiting this vulnerability allows valid users of the system to be listed and sensitive third-party information to be accessed, such as names, email addresses, internal identifiers, and last activity. The endpoint 'http://<IP>:12900/users/<my_user>' does not implement object-level authorization validations.

Basic Information

ID CVE-2026-1436
Source INCIBE
Published Feb 18, 2026 at 13:09
Modified Feb 18, 2026 at 13:11

Affected Product

Vendor Graylog
Product Graylog Web Interface
Version 2.2.3
Affected Versions Graylog Graylog Web Interface 2.2.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.