CVE-2026-55867 | Graylog up to 6.3.11/7.0.6/7.1.1 Token Revocation UsersResource.java UsersResource.revokeToken userId authorization
A vulnerability was found in Graylog up to 6.3.11/7.0.6/7.1.1. It has been rated as problematic. This vulnerability affects the function UsersResource.revokeToken of the file graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java of the component Token Revocation. This manipulation of the argument userId causes authorization bypass.
The identification of this vulnerability is CVE-2026-55867. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More