THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j769-9gv9-65gr (medium) — Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens

[GHSA] GHSA-j769-9gv9-65gr (medium) — Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens

highgithub_advisoriesPublished 2026-08-28

GHSA-j769-9gv9-65gr Severity: medium CVE: CVE-2026-55867

Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens

### Impact

Graylog contains an insecure direct object reference (IDOR) vulnerability in the token revocation endpoint. An authenticated user can delete access tokens belonging to other users, including service account tokens and administrator

Indicators of compromise

Original source: https://github.com/advisories/GHSA-j769-9gv9-65gr