Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java checks USERS_TOKENREMOVE permission against the attacker-controlled userId path parameter before resolving the token selected by idOrToken. An authenticated user can provide an authorized userId while accessTokenService.loadById() or accessTokenService.load() resolves a token belonging to another user, including a service account or administrator, after which accessTokenService.destroy() deletes that token without checking AccessToken.getUserName(). The issue does not expose token contents, but unauthorized deletion causes integrity impact and can disrupt access-token-based integrations. This issue is fixed in versions 6.3.12, 7.0.7, and 7.1.2.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55867.json",
"cwe_ids": [
"CWE-639"
],
"cna_assigner": "GitHub_M"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "6.2.0"
},
{
"fixed": "6.3.12"
},
{
"introduced": "7.0.0-alpha.1"
},
{
"fixed": "7.0.7"
},
{
"introduced": "7.1.0-alpha.1"
},
{
"fixed": "7.1.2"
}
]
}
[
{
"id": "CVE-2026-55867-2bc1f162",
"target": {
"file": "graylog2-server/src/test/java/org/graylog2/rest/resources/users/UsersResourceTest.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"295368719508396695023785709866863041565",
"271123227653825792802890504985920761783",
"193520922891013442279544008467245768823",
"95404190445655841866979607662353971351",
"237230490934632326664624861112730102690",
"123993329747089421496334943407972188652",
"75346638319631699244224929533130326618"
]
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/84b0ffa0bdf918f6edd2bb23a47254088634b1fc",
"signature_type": "Line"
},
{
"id": "CVE-2026-55867-5189ff5f",
"target": {
"file": "graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"198343310415006386537422207054284210802",
"172795118323590513781945283172438932199",
"335828493656977414860298202064652440164",
"334740112069284329908665999421806278592",
"242268432618238020999146333375926306333",
"258335049688956787604957068549566668503",
"232866151658578787972202196664451963619",
"18410288275292206068337962452299218730",
"942843258178895881071606268116120673",
"150560594450223640127881346758862433115",
"6006340583476593612749392589259554679",
"37548927507754163234360810516937138346",
"44583967945763920996826159524007252664",
"267920557632338034117803626447014332169",
"102216138070095780132096098821975062392"
]
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/e5accc5f4ce48bd61b84bb8e5a13d21f8eac3da5",
"signature_type": "Line"
},
{
"id": "CVE-2026-55867-5d8b98bb",
"target": {
"file": "graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"92649159899843690700169386539267723116",
"99234463948897691201042499467074891434",
"121913591008655909448279093711875224736",
"334740112069284329908665999421806278592",
"242268432618238020999146333375926306333",
"258335049688956787604957068549566668503",
"232866151658578787972202196664451963619",
"18410288275292206068337962452299218730",
"942843258178895881071606268116120673",
"150560594450223640127881346758862433115",
"6006340583476593612749392589259554679",
"37548927507754163234360810516937138346",
"44583967945763920996826159524007252664",
"267920557632338034117803626447014332169",
"102216138070095780132096098821975062392"
]
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/84b0ffa0bdf918f6edd2bb23a47254088634b1fc",
"signature_type": "Line"
},
{
"id": "CVE-2026-55867-8c7ecd89",
"target": {
"file": "graylog2-server/src/test/java/org/graylog2/rest/resources/users/UsersResourceTest.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"92921124607529843552514715159079035761",
"193051788338912352364759568719035942906",
"335895787483757360467808523278841275016",
"242907837181214563041323974111452824449",
"237230490934632326664624861112730102690",
"121453652057684229226839435699453882978",
"278861709566330121511268416884909914125"
]
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/4f280138b53dc3bbb5749213e8cb1c8e372f23a2",
"signature_type": "Line"
},
{
"id": "CVE-2026-55867-992a09b2",
"target": {
"file": "graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"92649159899843690700169386539267723116",
"99234463948897691201042499467074891434",
"121913591008655909448279093711875224736",
"334740112069284329908665999421806278592",
"242268432618238020999146333375926306333",
"258335049688956787604957068549566668503",
"232866151658578787972202196664451963619",
"18410288275292206068337962452299218730",
"942843258178895881071606268116120673",
"150560594450223640127881346758862433115",
"6006340583476593612749392589259554679",
"37548927507754163234360810516937138346",
"44583967945763920996826159524007252664",
"267920557632338034117803626447014332169",
"102216138070095780132096098821975062392"
]
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/41d3745d0e52736d06c07d279ca0d72c1616df4c",
"signature_type": "Line"
},
{
"id": "CVE-2026-55867-ab257330",
"target": {
"function": "revokeToken",
"file": "graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java"
},
"deprecated": false,
"digest": {
"function_hash": "103753533631485089146284062194198812524",
"length": 683.0
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/4f280138b53dc3bbb5749213e8cb1c8e372f23a2",
"signature_type": "Function"
},
{
"id": "CVE-2026-55867-d29b4025",
"target": {
"function": "revokeToken",
"file": "graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java"
},
"deprecated": false,
"digest": {
"function_hash": "103753533631485089146284062194198812524",
"length": 683.0
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/e5accc5f4ce48bd61b84bb8e5a13d21f8eac3da5",
"signature_type": "Function"
},
{
"id": "CVE-2026-55867-d304d26c",
"target": {
"file": "graylog2-server/src/test/java/org/graylog2/rest/resources/users/UsersResourceTest.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"295368719508396695023785709866863041565",
"271123227653825792802890504985920761783",
"193520922891013442279544008467245768823",
"95404190445655841866979607662353971351",
"237230490934632326664624861112730102690",
"123993329747089421496334943407972188652",
"75346638319631699244224929533130326618"
]
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/41d3745d0e52736d06c07d279ca0d72c1616df4c",
"signature_type": "Line"
},
{
"id": "CVE-2026-55867-f3b05c24",
"target": {
"function": "revokeToken",
"file": "graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java"
},
"deprecated": false,
"digest": {
"function_hash": "171503515837936334037705507065910067717",
"length": 685.0
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/41d3745d0e52736d06c07d279ca0d72c1616df4c",
"signature_type": "Function"
},
{
"id": "CVE-2026-55867-f63e4c9a",
"target": {
"file": "graylog2-server/src/test/java/org/graylog2/rest/resources/users/UsersResourceTest.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"295368719508396695023785709866863041565",
"294944023983977225180282478353803002383",
"300985597634701130340237784341980252820",
"242907837181214563041323974111452824449",
"237230490934632326664624861112730102690",
"242773901794039825549336031703396983133",
"219311786410835367189912993709208555881"
]
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/e5accc5f4ce48bd61b84bb8e5a13d21f8eac3da5",
"signature_type": "Line"
},
{
"id": "CVE-2026-55867-f994fa17",
"target": {
"function": "revokeToken",
"file": "graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java"
},
"deprecated": false,
"digest": {
"function_hash": "171503515837936334037705507065910067717",
"length": 685.0
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/84b0ffa0bdf918f6edd2bb23a47254088634b1fc",
"signature_type": "Function"
},
{
"id": "CVE-2026-55867-fc3e7c4e",
"target": {
"file": "graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"198343310415006386537422207054284210802",
"172795118323590513781945283172438932199",
"335828493656977414860298202064652440164",
"334740112069284329908665999421806278592",
"242268432618238020999146333375926306333",
"258335049688956787604957068549566668503",
"232866151658578787972202196664451963619",
"18410288275292206068337962452299218730",
"942843258178895881071606268116120673",
"150560594450223640127881346758862433115",
"6006340583476593612749392589259554679",
"37548927507754163234360810516937138346",
"44583967945763920996826159524007252664",
"267920557632338034117803626447014332169",
"102216138070095780132096098821975062392"
]
},
"signature_version": "v1",
"source": "https://github.com/graylog2/graylog2-server/commit/4f280138b53dc3bbb5749213e8cb1c8e372f23a2",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55867.json"
"2026-08-30T08:17:31Z"