
CVE-2026-1436 Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's prof… https://www.cve.org/CVERecord?id=CVE-2026-1436
Post summary
Graylog API v2.2.3 suffers from an IDOR flaw that lets an authenticated user change a user ID in the URL to view other users' profiles.
