CVE-2026-69190
Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grants owner permissions to an arbitrary account. The selected account can then delete the saved search or dashboard or remove the original owner's access. Graylog Cloud was patched before the advisory was published. This issue is fixed in versions 6.3.14, 7.0.9, and 7.1.4.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Base score: 6.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.42%
- Percentile among all scored CVEs: 34
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement85 % - Primary impact
T1078Valid Accountsstealth · persistence · privilege escalation · initial access90 % - Secondary impact
T1565.001Stored Data Manipulationimpact70 %
Explotación de API remota (T1210) por usuario autenticado sin ser propietario; impacto: obtención de permisos de propietario (T1078) y manipulación de recursos ajenos (T1565.001).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-639, CWE-862
References
- https://github.com/Graylog2/graylog2-server/commit/9303f395dd29c03abd8885f1c7d1c90f8aae72d4
- https://github.com/Graylog2/graylog2-server/commit/ac1c0b19e3f44c2eed8e95f4d398ba455e30a8f2
- https://github.com/Graylog2/graylog2-server/commit/c87879642537d07760a572ba01b76cb657582608
- https://github.com/Graylog2/graylog2-server/commit/e98c6670d05748a9749ab0646be7f40561734b42
- https://github.com/Graylog2/graylog2-server/pull/26344
- https://github.com/Graylog2/graylog2-server/releases/tag/6.3.14
- https://github.com/Graylog2/graylog2-server/releases/tag/7.0.9
- https://github.com/Graylog2/graylog2-server/releases/tag/7.1.4
- https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-m9c2-85gv-8xr5
Raw JSON (NVD)
Show
{
"id": "CVE-2026-69190",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-69190",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-21T19:01:52.176197Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "Graylog2",
"product": "graylog2-server",
"versions": [
{
"status": "affected",
"version": ">= 6.3.0, < 6.3.14"
},
{
"status": "affected",
"version": ">= 7.0.0, < 7.0.9"
},
{
"status": "affected",
"version": ">= 7.1.0, < 7.1.4"
}
]
}
]
}
],
"published": "2026-09-21T18:17:10.210",
"references": [
{
"url": "https://github.com/Graylog2/graylog2-server/commit/9303f395dd29c03abd8885f1c7d1c90f8aae72d4",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Graylog2/graylog2-server/commit/ac1c0b19e3f44c2eed8e95f4d398ba455e30a8f2",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Graylog2/graylog2-server/commit/c87879642537d07760a572ba01b76cb657582608",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Graylog2/graylog2-server/commit/e98c6670d05748a9749ab0646be7f40561734b42",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Graylog2/graylog2-server/pull/26344",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Graylog2/graylog2-server/releases/tag/6.3.14",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Graylog2/graylog2-server/releases/tag/7.0.9",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Graylog2/graylog2-server/releases/tag/7.1.4",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-m9c2-85gv-8xr5",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-639"
},
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grants owner permissions to an arbitrary account. The selected account can then delete the saved search or dashboard or remove the original owner's access. Graylog Cloud was patched before the advisory was published. This issue is fixed in versions 6.3.14, 7.0.9, and 7.1.4."
}
],
"lastModified": "2026-09-24T21:17:43.237",
"sourceIdentifier": "security-advisories@github.com"
}