CRITICAL🇵🇱 Wersja polska

CVE-2026-1435

CVSS 9.3v4.0pub. 2026-02-18

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or leaked 'sessionId' can continue to be used to authenticate valid requests. Exploiting this vulnerability would allow an attacker with access to the web service/API network (port 9000 or HTTP/S endpoint of the server) to reuse an old session token to gain unauthorized access to the application, interact with the API/web, and compromise the integrity of the affected account.

🤖 AI Analysis
How it works

The application generates a new session identifier ('sessionId') during each user authentication, however old session identifiers are not invalidated and remain active. An attacker who obtains a previously issued session token (e.g., through interception or a leak) can use it multiple times to authenticate requests to the API or web interface. The attack requires network access to the Graylog service on port 9000 or through the HTTP/HTTPS endpoint of the server.

Impact

An attacker can gain unauthorized access to the Graylog application, perform operations on the API and web interface, and compromise the integrity and confidentiality of the attacked user's account.

Mitigation & patch

Apply patches available from the vendor according to the references (https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-graylog). Additionally, it is recommended to force user re-authentication and audit active sessions to eliminate potentially compromised tokens.

Who is affected

Graylog Web Interface version 2.2.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Graylog

    APP
    Graylog
    2.2.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-37759CRITICAL9.8PL ✓same product

Wyciek Session ID w logach DEBUG w Graylog — eskalacja uprawnień

CVE-2021-37760CRITICAL9.8PL ✓same product

Wyciek Session ID w logu audytu Graylog — privilege escalation

CVE-2026-1436HIGH7.1same product

Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in t...

CVE-2025-53106HIGH8.8same product

Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to bef...

CVE-2025-46827HIGH8.0same product

Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possibl...