CVE-2026-69190
Last modified
CVE-2026-69190 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grants owner permissions to an arbitrary account. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grants owner permissions to an arbitrary account. The selected account can then delete the saved search or dashboard or remove the original owner's access. Graylog Cloud was patched before the advisory was published. This issue is fixed in versions 6.3.14, 7.0.9, and 7.1.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Graylog2 | graylog2-server | >= 6.3.0, < 6.3.14; >= 7.0.0, < 7.0.9; >= 7.1.0, < 7.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-69190?
How severe is CVE-2026-69190?
How do I fix CVE-2026-69190?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69183Monkeytype is a minimalistic and customizable typing test. I…7.5
- CVE-2026-69184c-ares is an asynchronous resolver library. Prior to 1.34.7,…7.5
- CVE-2026-69185Socket.IO enables bidirectional and low-latency communicatio…7.5
- CVE-2026-69186c-ares is an asynchronous resolver library. Prior to 1.34.7,…5.3
- CVE-2026-69189Hoppscotch is an open source API development ecosystem. Prio…7.6
- CVE-2026-6919Use after free in DevTools in Google Chrome prior to 147.0.7…9.6
- CVE-2026-69192ip-address is a library for parsing and manipulating IPv4 an…7.7
- CVE-2026-69197Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.…8.7
- CVE-2026-69198ip-address is a library for parsing and manipulating IPv4 an…6.9
- CVE-2026-6920Out of bounds read in GPU in Google Chrome on Android prior …9.6
- CVE-2026-69200node-opcua is an OPC UA implementation for TypeScript and No…3.7
- CVE-2026-69201Http4s is a Scala interface for HTTP services. Prior to 0.23…5.9
Are you affected by CVE-2026-69190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
