<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Graylog (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/graylog.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/graylog-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Graylog (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:00 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-1435 – Not properly invalidated session vulnerability in Graylog Web Interface, version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1435</guid>
    <pubDate>Wed, 18 Feb 2026 14:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1435</strong></p>
  <p>Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or l…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53106 – Graylog is a free and open log management platform. In versions 6.2.0 to before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53106</guid>
    <pubDate>Wed, 02 Jul 2025 14:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53106</strong></p>
  <p>Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated privileges by creating and using API tokens for the local Administrator or any other user for whom the malicious user knows the ID. For the attack to succeed, the attacker needs a user account in Graylog. They can then proceed to issue hand-…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46827 – Graylog is a free and open log management platform. Prior to versions 6.0.14, 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46827</guid>
    <pubDate>Wed, 07 May 2025 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46827</strong></p>
  <p>Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, the attacker needs a user account with permissions to create event definitions, while the user must have permissions to view alerts. Additionally,…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24824 – Graylog is a free and open log management platform. Starting in version 2.0.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24824</guid>
    <pubDate>Wed, 07 Feb 2024 18:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24824</strong></p>
  <p>Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses fully qualified class names as config keys. To validate the existence of the requested class before using them, Graylog loa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37760 – A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37760</guid>
    <pubDate>Sat, 31 Jul 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37760</strong></p>
  <p>A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37759 – A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37759</guid>
    <pubDate>Sat, 31 Jul 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37759</strong></p>
  <p>A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15813 – Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15813</guid>
    <pubDate>Fri, 17 Jul 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15813</strong></p>
  <p>Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connection configuration allows the usage of unencrypted, SSL- or TLS-secured connections. Unfortunately, the Graylog client code (in all versions that support LDAP) does not implement proper certificate validation (regardless of whether the "Allow self-sign…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15813">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
