CVE-2026-69190
Received Received - Intake

Privilege Escalation in Graylog via Shared Search Permissions

Vulnerability report for CVE-2026-69190, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: GitHub, Inc.

Description

Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grants owner permissions to an arbitrary account. The selected account can then delete the saved search or dashboard or remove the original owner's access. Graylog Cloud was patched before the advisory was published. This issue is fixed in versions 6.3.14, 7.0.9, and 7.1.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
graylog graylog From 6.3.0 (inc) to 6.3.14 (inc)
graylog graylog 7.0.9
graylog graylog 7.1.4
graylog graylog to 6.3.14 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Graylog allows a user with edit permissions but not ownership of a saved search or dashboard to modify its sharing settings. By including a shareRequest during an update, the user can grant owner permissions to an arbitrary account. This allows the new owner to delete the resource or remove the original owner's access. The issue affects versions 6.3.0 to 6.3.14, 7.0.9, and 7.1.4.

Detection Guidance

This vulnerability can be detected by checking the Graylog server version. If your version is between 6.3.0 and 6.3.14, 7.0.0 and 7.0.9, or 7.1.0 and 7.1.4, it is vulnerable. Run the command: curl -s http://<graylog-server>:9000/api/system | grep version to check the installed version.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to gain control over your saved searches or dashboards. They could delete important data or remove your access to critical resources. This could disrupt log management operations and lead to loss of visibility in your system.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized access to sensitive log data. GDPR requires protecting personal data, while HIPAA mandates securing health information. Unauthorized changes to dashboards or searches could lead to data breaches or improper access, violating these regulations.

Mitigation Strategies

Upgrade Graylog to versions 6.3.14, 7.0.9, or 7.1.4 or later to patch the vulnerability. Graylog Cloud is already patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69190. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart