A set of seven vulnerabilities affecting the Graylog Web Interface v2.2.3 was coordinated for public disclosure by INCIBE-CERT, including CVE-2026-1435 (CVSS v4.0 9.1, CWE-613) and additional issues CVE-2026-1436 (CVSS v4.0 7.0, CWE-284) plus CVE-2026-1437 through CVE-2026-1441 (CVSS v4.0 6.1, CWE-79). The flaws were reported as discovered by Julen Garrido Estévez (B3xal) and impact Graylog’s web UI component used for log management and security/IT operations.
Technical details published for CVE-2026-1435 indicate incorrect session invalidation: Graylog generates a new sessionId on each login but does not invalidate previously issued session identifiers, allowing a stolen/leaked old token to remain usable for authenticated requests. An attacker with network access to the Graylog web service/API (e.g., port 9000 or the server’s HTTP/S endpoint) could reuse an old sessionId to gain unauthorized access and act via the web UI/API under the affected account. INCIBE-CERT recommends updating to a patched/current Graylog version, noting older versions are considered obsolete and are not otherwise mitigated.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A vulnerability affecting the Graylog Web Interface version 2.2.3 was publicly disclosed as CVE-2026-1435. The flaw allows previously issued session identifiers to remain valid after subsequent logins, creating a risk of unauthorized access if a session ID is stolen or leaked.
INCIBE-CERT issued an alert warning about multiple vulnerabilities in Graylog. The advisory indicates broader public reporting and awareness of security issues affecting the product.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.