CVE-2026-1435

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or leaked 'sessionId' can continue to be used to authenticate valid requests. Exploiting this vulnerability would allow an attacker with access to the web service/API network (port 9000 or HTTP/S endpoint of the server) to reuse an old session token to gain unauthorized access to the application, interact with the API/web, and compromise the integrity of the affected account.
Configurations

Configuration 1 (hide)

cpe:2.3:a:graylog:graylog:2.2.3:*:*:*:*:*:*:*

History

17 Jun 2026, 10:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de sesión no invalidada correctamente en la interfaz web de Graylog, versión 2.2.3, debido a una gestión incorrecta de la invalidación de la sesión después de nuevos inicios de sesión. La aplicación genera un nuevo 'sessionId' cada vez que un usuario se autentica, pero no invalida los identificadores de sesión emitidos previamente, los cuales permanecen válidos incluso después de múltiples inicios de sesión consecutivos por el mismo usuario. Como resultado, un 'sessionId' robado o filtrado puede seguir siendo utilizado para autenticar solicitudes válidas. La explotación de esta vulnerabilidad permitiría a un atacante con acceso a la red del servicio web/API (puerto 9000 o punto final HTTP/S del servidor) reutilizar un token de sesión antiguo para obtener acceso no autorizado a la aplicación, interactuar con la API/web, y comprometer la integridad de la cuenta afectada.

18 Feb 2026, 20:22

Type Values Removed Values Added
First Time Graylog
Graylog graylog
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-graylog - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-graylog - Third Party Advisory
CPE cpe:2.3:a:graylog:graylog:2.2.3:*:*:*:*:*:*:*

18 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 14:16

Updated : 2026-06-17 10:15


NVD link : CVE-2026-1435

Mitre link : CVE-2026-1435

CVE.ORG link : CVE-2026-1435


JSON object : View

Products Affected

graylog

  • graylog
CWE
CWE-613

Insufficient Session Expiration