CVE-2026-82437: Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For
Summary
A vulnerability in Logviewer (a log viewing system) allowed unauthorized access to daemon logs because access control rules were ignored for those specific logs, even though they work correctly for other log types. This meant any user who passed basic authentication could read sensitive logs containing other users' topology names, owners, and configuration details across the system.
Solution / Mitigation
Upgrade to version 3.1.0, where daemon log paths now apply the same user and group access controls that worker log paths already use, and listing endpoints filter results by the requesting user. For users unable to upgrade immediately, place the Logviewer behind a reverse proxy (a server that sits between users and the application to control access) that restricts daemon log endpoints, and treat daemon log content as readable by any filter-authenticated user.
Vulnerability Details
EPSS: 0.0%
September 14, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82437
First tracked: September 14, 2026 at 02:11 PM
Classified by LLM (prompt v3) · confidence: 95%