Impact
A user with edit permissions, but not ownership, can submit an update to a saved search or dashboard that includes a shareRequest granting owner rights to an arbitrary account. The added owner can delete the resource or remove the original owner's access. This flaw enables unauthorized privilege escalation and compromise of configuration integrity. The vulnerability is related to CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-862 (Missing Authorization).
Affected Systems
Graylog Server versions 6.3.0 through 6.3.14, 7.0.9, and 7.1.4 are affected. The issue was patched in Graylog Cloud before the advisory was published. Users running older builds of these releases are vulnerable unless they have upgraded.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. The EPSS score is not available, so the prevalence of exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. Attackers would need valid credentials with edit access to a saved search or dashboard; exploitation then proceeds via the HTTP API by including a malicious shareRequest. The flaw can be leveraged remotely provided the API is reachable from the attacker’s environment.
OpenCVE Enrichment