THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q79r-r9xg-r863 (medium) — Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields

[GHSA] GHSA-q79r-r9xg-r863 (medium) — Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields

medgithub_advisoriesPublished 2026-08-28

GHSA-q79r-r9xg-r863 Severity: medium CVE: CVE-2026-55425

Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields

### Impact

A vulnerability was found in Graylog's API endpoint for retrieving system catalog entity titles. Authenticated users could retrieve database fields of supported entities by sending a custom API request. These fields can in

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q79r-r9xg-r863