« Back to list

CVE-2026-69190

Status: Awaiting AnalysisMedium (6.3)—

Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grants owner permissions to an arbitrary account. The selected account can then delete the saved search or dashboard or remove the original owner's access. Graylog Cloud was patched before the advisory was published. This issue is fixed in versions 6.3.14, 7.0.9, and 7.1.4.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Explotación de API remota (T1210) por usuario autenticado sin ser propietario; impacto: obtención de permisos de propietario (T1078) y manipulación de recursos ajenos (T1565.001).

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-69190",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-69190",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-21T19:01:52.176197Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "Graylog2",
          "product": "graylog2-server",
          "versions": [
            {
              "status": "affected",
              "version": ">= 6.3.0, < 6.3.14"
            },
            {
              "status": "affected",
              "version": ">= 7.0.0, < 7.0.9"
            },
            {
              "status": "affected",
              "version": ">= 7.1.0, < 7.1.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-21T18:17:10.210",
  "references": [
    {
      "url": "https://github.com/Graylog2/graylog2-server/commit/9303f395dd29c03abd8885f1c7d1c90f8aae72d4",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Graylog2/graylog2-server/commit/ac1c0b19e3f44c2eed8e95f4d398ba455e30a8f2",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Graylog2/graylog2-server/commit/c87879642537d07760a572ba01b76cb657582608",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Graylog2/graylog2-server/commit/e98c6670d05748a9749ab0646be7f40561734b42",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Graylog2/graylog2-server/pull/26344",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Graylog2/graylog2-server/releases/tag/6.3.14",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Graylog2/graylog2-server/releases/tag/7.0.9",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Graylog2/graylog2-server/releases/tag/7.1.4",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-m9c2-85gv-8xr5",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        },
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grants owner permissions to an arbitrary account. The selected account can then delete the saved search or dashboard or remove the original owner's access. Graylog Cloud was patched before the advisory was published. This issue is fixed in versions 6.3.14, 7.0.9, and 7.1.4."
    }
  ],
  "lastModified": "2026-09-24T21:17:43.237",
  "sourceIdentifier": "security-advisories@github.com"
}