CVE-2026-55425: GRAYLOG2 GRAYLOG2-Server

Medium severity, CVSS 5.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java allows an authenticated user to request composite display fields without verifying that every selected field is readable. A user can retrieve protected values, including the password hash on a readable user record; ordinary users are limited to their own permitted records, while administrators can retrieve hashes for all users. This issue is fixed in versions 7.1.4 and 7.2.0-alpha.2.

Affected products

  • GRAYLOG2 GRAYLOG2-Server: from 7.1.0, before 7.1.4 (fixed in 7.1.4); from 7.2.0-alpha.1, before 7.2.0-alpha.2 (fixed in 7.2.0-alpha.2)

Published 2026-08-28. Last modified 2026-09-09.