THREAT OPS › Threat News › [GHSA] GHSA-q79r-r9xg-r863 (medium) — Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
[GHSA] GHSA-q79r-r9xg-r863 (medium) — Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
GHSA-q79r-r9xg-r863 Severity: medium CVE: CVE-2026-55425
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
### Impact
A vulnerability was found in Graylog's API endpoint for retrieving system catalog entity titles. Authenticated users could retrieve database fields of supported entities by sending a custom API request. These fields can in
Indicators of compromise
- CVE-2026-55425cve
Original source: https://github.com/advisories/GHSA-q79r-r9xg-r863