{"id":"CVE-2026-55867","title":"Graylog is a free and open log management platform","summary":"Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog…","severity":"medium","cwe":["CWE-639"],"vendor":"graylog2","product":"org.graylog2:graylog2-server","affected":["org.graylog2:graylog2-server >= 6.2.0, < 6.3.12","org.graylog2:graylog2-server >= 7.0.0, < 7.0.7","org.graylog2:graylog2-server >= 7.1.0, < 7.1.2"],"patched":["org.graylog2:graylog2-server 6.3.12","org.graylog2:graylog2-server 7.0.7","org.graylog2:graylog2-server 7.1.2"],"published":"2026-08-28","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:09:13.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55867","references":[{"url":"https://github.com/Graylog2/graylog2-server/commit/41d3745d0e52736d06c07d279ca0d72c1616df4c","label":"security-advisories@github.com"},{"url":"https://github.com/Graylog2/graylog2-server/commit/4f280138b53dc3bbb5749213e8cb1c8e372f23a2","label":"security-advisories@github.com"},{"url":"https://github.com/Graylog2/graylog2-server/commit/84b0ffa0bdf918f6edd2bb23a47254088634b1fc","label":"security-advisories@github.com"},{"url":"https://github.com/Graylog2/graylog2-server/commit/e5accc5f4ce48bd61b84bb8e5a13d21f8eac3da5","label":"security-advisories@github.com"},{"url":"https://github.com/Graylog2/graylog2-server/pull/26049","label":"security-advisories@github.com"},{"url":"https://github.com/Graylog2/graylog2-server/pull/26051","label":"security-advisories@github.com"},{"url":"https://github.com/Graylog2/graylog2-server/pull/26053","label":"security-advisories@github.com"},{"url":"https://github.com/Graylog2/graylog2-server/pull/26055","label":"security-advisories@github.com"},{"url":"https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-j769-9gv9-65gr","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-j769-9gv9-65gr"}],"tags":["nvd","ghsa","maven"],"epss":0.00335,"epssPercentile":0.26949,"aliases":["GHSA-j769-9gv9-65gr"],"ecosystem":"maven","ingestedAt":"2026-08-28T22:26:19.039Z","slug":"CVE-2026-55867","body":"## Overview\n\nGraylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java checks USERS_TOKENREMOVE permission against the attacker-controlled userId path parameter before resolving the token selected by idOrToken. An authenticated user can provide an authorized userId while accessTokenService.loadById() or accessTokenService.load() resolves a token belonging to another user, including a service account or administrator, after which accessTokenService.destroy() deletes that token without checking AccessToken.getUserName(). The issue does not expose token contents, but unauthorized deletion causes integrity impact and can disrupt access-token-based integrations. This issue is fixed in versions 6.3.12, 7.0.7, and 7.1.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-55867)\n\nAffected packages:\n\n- `org.graylog2:graylog2-server >= 6.2.0, < 6.3.12`\n- `org.graylog2:graylog2-server >= 7.0.0, < 7.0.7`\n- `org.graylog2:graylog2-server >= 7.1.0, < 7.1.2`\n\nPatched in:\n\n- `org.graylog2:graylog2-server 6.3.12`\n- `org.graylog2:graylog2-server 7.0.7`\n- `org.graylog2:graylog2-server 7.1.2`\n\nSource: https://github.com/advisories/GHSA-j769-9gv9-65gr","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}