Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-1435

Опубликовано: 18 фев. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or leaked 'sessionId' can continue to be used to authenticate valid requests. Exploiting this vulnerability would allow an attacker with access to the web service/API network (port 9000 or HTTP/S endpoint of the server) to reuse an old session token to gain unauthorized access to the application, interact with the API/web, and compromise the integrity of the affected account.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:graylog:graylog:2.2.3:*:*:*:*:*:*:*

EPSS

Процентиль: 22%
0.00071
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.8
debian
около 2 месяцев назад

Not properly invalidated session vulnerability in Graylog Web Interfac ...

CVSS3: 9.8
github
около 2 месяцев назад

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or leaked 'sessionId' can continue to be used to authenticate valid requests. Exploiting this vulnerability would allow an attacker with access to the web service/API network (port 9000 or HTTP/S endpoint of the server) to reuse an old session token to gain unauthorized access to the application, interact with the API/web, and compromise the integrity of the affected account.

EPSS

Процентиль: 22%
0.00071
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-613