---
id: CVE-2026-55867
title: Graylog is a free and open log management platform
summary: >-
  Graylog is a free and open log management platform. From 6.2.0 until 6.3.12,
  7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint
  implemented by UsersResource.revokeToken() in
  graylog2-server/src/main/java/org/graylog…
severity: medium
cwe:
  - CWE-639
vendor: graylog2
product: 'org.graylog2:graylog2-server'
affected:
  - 'org.graylog2:graylog2-server >= 6.2.0, < 6.3.12'
  - 'org.graylog2:graylog2-server >= 7.0.0, < 7.0.7'
  - 'org.graylog2:graylog2-server >= 7.1.0, < 7.1.2'
patched:
  - 'org.graylog2:graylog2-server 6.3.12'
  - 'org.graylog2:graylog2-server 7.0.7'
  - 'org.graylog2:graylog2-server 7.1.2'
published: '2026-08-28'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:09:13.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55867'
references:
  - url: >-
      https://github.com/Graylog2/graylog2-server/commit/41d3745d0e52736d06c07d279ca0d72c1616df4c
    label: security-advisories@github.com
  - url: >-
      https://github.com/Graylog2/graylog2-server/commit/4f280138b53dc3bbb5749213e8cb1c8e372f23a2
    label: security-advisories@github.com
  - url: >-
      https://github.com/Graylog2/graylog2-server/commit/84b0ffa0bdf918f6edd2bb23a47254088634b1fc
    label: security-advisories@github.com
  - url: >-
      https://github.com/Graylog2/graylog2-server/commit/e5accc5f4ce48bd61b84bb8e5a13d21f8eac3da5
    label: security-advisories@github.com
  - url: 'https://github.com/Graylog2/graylog2-server/pull/26049'
    label: security-advisories@github.com
  - url: 'https://github.com/Graylog2/graylog2-server/pull/26051'
    label: security-advisories@github.com
  - url: 'https://github.com/Graylog2/graylog2-server/pull/26053'
    label: security-advisories@github.com
  - url: 'https://github.com/Graylog2/graylog2-server/pull/26055'
    label: security-advisories@github.com
  - url: >-
      https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-j769-9gv9-65gr
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-j769-9gv9-65gr'
tags:
  - nvd
  - ghsa
  - maven
epss: 0.00335
epssPercentile: 0.27045
aliases:
  - GHSA-j769-9gv9-65gr
ecosystem: maven
ingestedAt: '2026-08-28T22:26:19.039Z'
---

## Overview

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java checks USERS_TOKENREMOVE permission against the attacker-controlled userId path parameter before resolving the token selected by idOrToken. An authenticated user can provide an authorized userId while accessTokenService.loadById() or accessTokenService.load() resolves a token belonging to another user, including a service account or administrator, after which accessTokenService.destroy() deletes that token without checking AccessToken.getUserName(). The issue does not expose token contents, but unauthorized deletion causes integrity impact and can disrupt access-token-based integrations. This issue is fixed in versions 6.3.12, 7.0.7, and 7.1.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-55867)

Affected packages:

- `org.graylog2:graylog2-server >= 6.2.0, < 6.3.12`
- `org.graylog2:graylog2-server >= 7.0.0, < 7.0.7`
- `org.graylog2:graylog2-server >= 7.1.0, < 7.1.2`

Patched in:

- `org.graylog2:graylog2-server 6.3.12`
- `org.graylog2:graylog2-server 7.0.7`
- `org.graylog2:graylog2-server 7.1.2`

Source: https://github.com/advisories/GHSA-j769-9gv9-65gr
