THREAT OPS › Threat News › [GHSA] GHSA-j769-9gv9-65gr (medium) — Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
[GHSA] GHSA-j769-9gv9-65gr (medium) — Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
GHSA-j769-9gv9-65gr Severity: medium CVE: CVE-2026-55867
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
### Impact
Graylog contains an insecure direct object reference (IDOR) vulnerability in the token revocation endpoint. An authenticated user can delete access tokens belonging to other users, including service account tokens and administrator
Indicators of compromise
- CVE-2026-55867cve
- https://go2docs.graylog.org/current/interacting_with_your_log_data/audit_log.htmlurl
Original source: https://github.com/advisories/GHSA-j769-9gv9-65gr