GHSA-j769-9gv9-65gr: Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Summary
Graylog has an IDOR vulnerability (insecure direct object reference, where an attacker can access resources belonging to other users by guessing or knowing their IDs) in its token revocation endpoint. Any authenticated user can delete access tokens (credentials that allow systems to authenticate without using passwords) belonging to other users, including administrator tokens, if they know the token's identifier, which could disrupt integrations and system access.
Solution / Mitigation
Upgrade to Graylog version 6.3.12, 7.0.7, 7.1.2, or above. Graylog Cloud has already been patched. Enterprise or Security users can check the audit log for suspicious activity by searching for log lines beginning with 'access token deleted from user'.
Vulnerability Details
EPSS: 0.0%
Yes
August 28, 2026
Classification
Affected Vendors
Affected Packages
Original source: https://github.com/advisories/GHSA-j769-9gv9-65gr
First tracked: August 28, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%