CVE-2026-65011 | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them.
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them.
- 🔗 github.com/Graylog2/graylog2-server/issues/26590
- 🔗 github.com/Graylog2/graylog2-server/pull/26706
- 🔗 github.com/Graylog2/graylog2-server/commit/46a2eeba4…
- 🔗 github.com/Graylog2/graylog2-server/pull/26718
- 🔗 github.com/Graylog2/graylog2-server/pull/26719
- 🔗 www.vulncheck.com/advisories/graylog2-server-missing-permis…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-14 | 2026-09-27 |
|---|---|---|
| ≥90 % | 0 | 497 |
| ≥50 % | 0 | 1468 |
| ≥10 % | 0 | 4 |
| <10 % | 300 | 297 |
CVE-2026-65011 | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them.
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-pri
Noch keine Analyse zu CVE-2026-65011
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.