GHSA-q79r-r9xg-r863: Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
Summary
Graylog Server has a vulnerability in its system catalog API endpoint that allows authenticated users to retrieve sensitive database fields they shouldn't have access to, such as password hashes (the encrypted version of a password). While permission checks still exist (regular users can only see their own hashes, but admins can see everyone's), these protected fields should never be returned through this API endpoint.
Solution / Mitigation
This issue has been patched in Graylog 7.1.4. In this version, an allow list (a list of approved fields that are permitted to be accessed) will be used to check if protected fields are being accessed, refusing those requests. Affected users should upgrade to 7.1.4 or above to remediate the vulnerability. There is no known workaround.
Vulnerability Details
EPSS: 0.0%
Yes
August 28, 2026
Classification
Affected Vendors
Affected Packages
Original source: https://github.com/advisories/GHSA-q79r-r9xg-r863
First tracked: August 28, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%