Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Summary
| CVE | CVE-2026-55867 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 23:17:09 UTC |
| Updated | 2026-08-28 23:17:09 UTC |
| Description | Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java checks USERS_TOKENREMOVE permission against the attacker-controlled userId path parameter before resolving the token selected by idOrToken. An authenticated user can provide an authorized userId while accessTokenService.loadById() or accessTokenService.load() resolves a token belonging to another user, including a service account or administrator, after which accessTokenService.destroy() deletes that token without checking AccessToken.getUserName(). The issue does not expose token contents, but unauthorized deletion causes integrity impact and can disrupt access-token-based integrations. This issue is fixed in versions 6.3.12, 7.0.7, and 7.1.2. |
Risk And Classification
Primary CVSS: v4.0 5.3 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-639 | CWE-639 CWE-639: Authorization Bypass Through User-Controlled Key
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
NoneIntegrity
LowAvailability
LowSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Graylog2 | Graylog2-server | affected >= 6.2.0, < 6.3.12 | Not specified |
| CNA | Graylog2 | Graylog2-server | affected >= 7.0.0-alpha.1, < 7.0.7 | Not specified |
| CNA | Graylog2 | Graylog2-server | affected >= 7.1.0-alpha.1, < 7.1.2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/Graylog2/graylog2-server/commit/4f280138b53dc3bbb5749213e8cb1... | [email protected] | github.com | |
| github.com/Graylog2/graylog2-server/commit/e5accc5f4ce48bd61b84bb8e5a13d... | [email protected] | github.com | |
| github.com/Graylog2/graylog2-server/pull/26053 | [email protected] | github.com | |
| github.com/Graylog2/graylog2-server/pull/26051 | [email protected] | github.com | |
| github.com/Graylog2/graylog2-server/commit/84b0ffa0bdf918f6edd2bb23a4725... | [email protected] | github.com | |
| github.com/Graylog2/graylog2-server/pull/26049 | [email protected] | github.com | |
| github.com/Graylog2/graylog2-server/commit/41d3745d0e52736d06c07d279ca0d... | [email protected] | github.com | |
| github.com/Graylog2/graylog2-server/security/advisories/GHSA-j769-9gv9-65gr | [email protected] | github.com | |
| github.com/Graylog2/graylog2-server/pull/26055 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.