CVE-2026-65011
MEDIUM
4.3
CVSS 3.1
Description
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them.
Metadata
Severity & Metrics
4.3
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Graylog2 | graylog2-server | — | 0 ≤ 7.1.5, 0 ≤ 7.0.10, 46a2eeba4cdbc1408ff4cbf7b466853a8acfb38d |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-862 | cna | Missing Authorization |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.3 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| 4.3 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
References (6)
- Researcher Disclosure https://github.com/Graylog2/graylog2-server/issues/26590
- Pull Request https://github.com/Graylog2/graylog2-server/pull/26706
- Patch Commit https://github.com/Graylog2/graylog2-server/commit/46a2eeba4cdbc1408ff4cbf7b466853a8acfb38d
- 7.0 Backport Fix https://github.com/Graylog2/graylog2-server/pull/26718
- 7.1 Backport Fix https://github.com/Graylog2/graylog2-server/pull/26719
- https://www.vulncheck.com/advisories/graylog2-server-missing-permission-check-on-event-definition-duplicate