CVE-2025-53106 Details
Description
Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated privileges by creating and using API tokens for the local Administrator or any other user for whom the malicious user knows the ID. For the attack to succeed, the attacker needs a user account in Graylog. They can then proceed to issue hand-crafted requests to the Graylog REST API and exploit a weak permission check for token creation. This issue has been patched in versions 6.2.4 and 6.3.0-rc.2. A workaround involves disabling the respective configuration found in System > Configuration > Users > "Allow users to create personal access tokens".
A privilege escalation vulnerability has been identified in Graylog, a log management platform, affecting versions 6.2.0 prior to 6.2.4 and 6.3.0-alpha.1 prior to 6.3.0-rc.2. The vulnerability allows users to create API tokens for the local Administrator or any other user, provided the user ID is known. This exploitation takes advantage of a weak permission check in the token creation process. To successfully exploit this vulnerability, an attacker must have a user account in Graylog.
Users can upgrade to Graylog versions 6.2.4 or 6.3.0-rc.2, where this vulnerability has been patched. After upgrading, it is recommended to review the API tokens in the Token Management section to ensure they are all accounted for and necessary. Graylog Enterprise users should check the Audit Log for any token creation actions during the period the vulnerability was present.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| graylog graylog | >= 6.2.0, < 6.2.4 6.3.0 - 6.3.0 alpha1 6.3.0 alpha2 6.3.0 alpha3 6.3.0 alpha4 6.3.0 beta1 6.3.0 beta2 6.3.0 beta3 6.3.0 beta4 6.3.0 beta5 6.3.0 rc1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 30, 2025 | Initial Analysis | [email protected] |
| Jul 2, 2025 | New CVE Received | [email protected] |