CVE-2026-1435Disclosure(graylog / graylog)

LOWCVSS 9.8 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch graylog graylog systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or leaked 'sessionId' can continue to be used to authenticate valid requests. Exploiting this vulnerability would allow an attacker with access to the web service/API network (port 9000 or HTTP/S endpoint of the server) to reuse an old session token to gain unauthorized access to the application, interact with the API/web, and compromise the integrity of the affected account.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • graylog

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
graylog

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-02-18: 5Patch / Workaround · 2026-02-18: 2Technical Details · 2026-02-18: 502-18
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1435 Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The applic… https://www.cve.org/CVERecord?id=CVE-2026-1435

    Post summary

    The text announces CVE-2026-1435, a session invalidation flaw in Graylog Web Interface v2.2.3, but provides no PoC, exploitation, patch, or active exploitation information.

    00020246
    56.4K followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Patch

    CVE-2026-1435 i Graylog Web Interface avslöjar allvarlig sessionhanteringsbrist, där sårbara session-ID kan återanvändas av angripare, vilket ger obehörig åtkomst. Viktigt att uppdatera för att åtgärda detta! #säkerhet #cybersäkerhet #CVE

    Post summary

    The post warns of a session‑ID reuse vulnerability in Graylog’s web interface (CVE‑2026‑1435) and urges users to apply updates to mitigate the flaw.

    0000020
    7 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1435 - Critical Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a ne... https://www.thehackerwire.com/vulnerability/CVE-2026-1435/ https://t.co/NzUY6mfabY

    Post summary

    The post announces CVE‑2026‑1435 as a critical session‑management vulnerability in Graylog Web Interface 2.2.3, providing technical details but no evidence of exploitation or mitigation.

    0000048
    112 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: Graylog Web Interface 2.2.3 exposes sessions to hijacking due to insufficient expiration. Attackers with network access can reuse stolen tokens for unauthorized entry. Restrict access & monitor sessions now! https://radar.offseq.com/threat/cve-2026-1435-cwe-613-ins... https://t.co/PO77La5xn1

    Post summary

    Graylog Web Interface 2.2.3 CVE‑2026‑1435 allows session hijacking via insufficient expiration; attackers can reuse stolen tokens, so users should restrict access and monitor sessions immediately.

    0000032
    265 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1435: Incorrect management of session i... Graylog's persistent sessionId tokens create perfect post-exploitation persistence—every login spawns new tokens without... https://zerodaysignal.com/vulnerability/CVE-2026-1435 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Graylog’s sessionId token handling flaw (CVE‑2026‑1435) has been disclosed, indicating post‑exploitation persistence, but no PoC, exploit, patch, or active exploitation is reported.

    0000045
    131 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgrayloggraylog2.2.3--

Explore more