CVE-2026-55425

Published: Ago 28, 2026 Last Modified: Ago 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,0
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: low
Integrity: none
Availability: none

Description

AI Translation Available

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java allows an authenticated user to request composite display fields without verifying that every selected field is readable. A user can retrieve protected values, including the password hash on a readable user record; ordinary users are limited to their own permitted records, while administrators can retrieve hashes for all users. This issue is fixed in versions 7.1.4 and 7.2.0-alpha.2.

213

Exposure of Sensitive Information Due to Incompatible Policies

Draft
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/Graylog2/graylog2-server/commit/1d1a91d99c3d2d8993e61c3c5234…
https://github.com/Graylog2/graylog2-server/commit/da7767a44233b6a683d0713eed08…
https://github.com/Graylog2/graylog2-server/pull/26284
https://github.com/Graylog2/graylog2-server/releases/tag/7.1.4
https://github.com/Graylog2/graylog2-server/releases/tag/7.2.0-alpha.2
https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-q79r-r9xg-…