🔐 CVE Alert

CVE-2026-1436

UNKNOWN 0.0

Improper Access Control (IDOR) vulnerability in Graylog Web Interface

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
9th

Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without proper authorization checks. Exploiting this vulnerability allows valid users of the system to be listed and sensitive third-party information to be accessed, such as names, email addresses, internal identifiers, and last activity. The endpoint 'http://<IP>:12900/users/<my_user>' does not implement object-level authorization validations.

CWE CWE-639
Vendor graylog
Product graylog web interface
Published Feb 18, 2026
Last Updated Feb 18, 2026
Stay Ahead of the Next One

Get instant alerts for graylog graylog web interface

Be the first to know when new unknown vulnerabilities affecting graylog graylog web interface are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Graylog / Graylog Web Interface
2.2.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-graylog

Credits

Julen Garrido Estévez (B3xal)