Vulnerabilities in Graylog2

15 results
Vexday analysis

Graylog2 apresenta 10 vulnerabilidades catalogadas, com 1 publicada nos últimos 90 dias, mas nenhuma sob exploração ativa confirmada (KEV) e sem críticas de CVSS. A fraqueza dominante é falha em autorização (CWE-285), indicando risco moderado concentrado em controles de acesso que requerem atenção em ambientes de produção.

CVE-2024-24824HIGHgraylog2-server vulnerable to instantiation of arbitrary classes triggered by API requestEPSS 34.7%CVE-2023-41044LOWPartial path traversal vulnerability in Support Bundle feature of GraylogEPSS 0.7%CVE-2026-55841HIGHGraylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original messageEPSS 0.6%CVE-2024-52506HIGHGraylog can leak other users' reports via concurrent PDF report renderingEPSS 0.6%CVE-2025-53106HIGHGraylog vulnerable to privilege escalation through API tokensEPSS 0.6%CVE-2026-55867MEDIUMGraylog token revocation endpoint allows authenticated users to delete other users’ access tokensEPSS 0.6%CVE-2023-41041LOWUser session is still usable after logout in graylog2-server EPSS 0.5%CVE-2026-69190MEDIUMGraylog: Manager-to-Owner privilege escalation on saved searches and dashboardsEPSS 0.4%CVE-2026-92789HIGHGraylog through 7.1.4 Server-Side Request Forgery via HTTP RedirectEPSS 0.4%CVE-2024-24823MEDIUMgraylog2-server Session Fixation vulnerability through cookie injectionEPSS 0.4%CVE-2026-55425MEDIUMGraylog: System Catalog titles endpoint can be used to retrieve values of protected database fieldsEPSS 0.4%CVE-2026-65011MEDIUMGraylog2 Server Missing Permission Check on Event Definition DuplicateEPSS 0.4%CVE-2023-41045LOWInsecure source port usage for DNS queries in GraylogEPSS 0.4%CVE-2025-30373MEDIUMGraylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong valueEPSS 0.3%CVE-2025-46827HIGHGraylog Allows Session Takeover via Insufficient HTML SanitizationEPSS 0.3%