Executive brief
Graylog is a widely-used log management and analysis platform. A flaw in its token management system allows any authenticated user to delete other users' access tokens if they know the token identifier, potentially disrupting integrations and administrative access. This could impact operational security and cause service disruptions for organizations using token-based authentication with Graylog.
Technical details
This is an insecure direct object reference (IDOR) vulnerability (CWE-639) in Graylog's token revocation API endpoint. An authenticated attacker with low privileges can craft requests to delete access tokens belonging to other users, including service accounts and administrators, by guessing or knowing valid token identifiers. The vulnerability requires prior authentication and network access to the Graylog API but does not require user interaction. The attack does not expose token contents but enables denial of service and integrity violations for token-based integrations. Patches are available in Graylog versions 6.3.12, 7.0.7, and 7.1.2 or later.
Affected products
- Graylog Graylog Server 6.2.0 to 6.3.11, 7.0.0 to 7.0.6, 7.1.0 to 7.1.1
Timeline
- 2026-06-24: disclosed: Published to GitHub Advisory Database
- 2026-08-28: advisory: Advisory updated and reviewed
- 2026-06-24: patched: Patches released in versions 6.3.12, 7.0.7, and 7.1.2
References
- https://api.github.com/users/michaelddickenson
- https://github.com/michaelddickenson
- https://api.github.com/users/michaelddickenson/gists%7B/gist_id%7D
- https://api.github.com/users/michaelddickenson/repos
- https://avatars.githubusercontent.com/u/132625804?v=4
- https://api.github.com/users/michaelddickenson/events%7B/privacy%7D