Graylog develops a centralized log management and analysis platform widely deployed in enterprise security operations and compliance environments, concentrating its vulnerability footprint in a single core product. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and they recur across predictable application-layer weakness classes: cross-site scripting, improper authorization, insufficient session management, and the inadvertent logging of sensitive data. These flaws reflect the dual exposure inherent to a web-facing data-aggregation service—the complexity of parsing and neutralizing untrusted log inputs while maintaining granular access controls across multi-tenant deployments. Defenders should treat Graylog advisories as a priority for internet-reachable infrastructure and review both access-control configurations and the scope of data flowing into the platform. Live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graylog over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24824HIGH Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP | Feb 7, 2024 | 8.8 | 41 | NO | NO |
CVE-2026-1435CRITICAL Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application genera | Feb 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2021-37759CRITICAL A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID). | Jul 31, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-37760CRITICAL A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID). | Jul 31, 2021 | 9.8 | 30 | NO | NO |
CVE-2025-53106HIGH Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated privileges by creating | Jul 2, 2025 | 8.8 | 25 | NO | NO |
CVE-2026-1436MEDIUM Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without | Feb 18, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-1441MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several | Feb 18, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-1439MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several | Feb 18, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-1438MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several | Feb 18, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-1437MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several | Feb 18, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graylog.
Media articles that mention a CVE ID that affects a product developed by Graylog — matched by CVE ID, not by vendor name.