{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-55841","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-06-17T16:29:38.865Z","datePublished":"2026-08-28T22:11:08.747Z","dateUpdated":"2026-09-01T02:03:04.137Z"},"containers":{"cna":{"title":"Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message","problemTypes":[{"descriptions":[{"cweId":"CWE-138","lang":"en","description":"CWE-138: Improper Neutralization of Special Elements","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-gqr6-r77p-c2pj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-gqr6-r77p-c2pj"},{"name":"https://github.com/Graylog2/graylog2-server/pull/26050","tags":["x_refsource_MISC"],"url":"https://github.com/Graylog2/graylog2-server/pull/26050"},{"name":"https://github.com/Graylog2/graylog2-server/pull/26056","tags":["x_refsource_MISC"],"url":"https://github.com/Graylog2/graylog2-server/pull/26056"},{"name":"https://github.com/Graylog2/graylog2-server/pull/26057","tags":["x_refsource_MISC"],"url":"https://github.com/Graylog2/graylog2-server/pull/26057"},{"name":"https://github.com/Graylog2/graylog2-server/pull/26059","tags":["x_refsource_MISC"],"url":"https://github.com/Graylog2/graylog2-server/pull/26059"},{"name":"https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8a775961dd3f","tags":["x_refsource_MISC"],"url":"https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8a775961dd3f"},{"name":"https://github.com/Graylog2/graylog2-server/commit/85dc699d6319aea433583dc239077a3a799c8627","tags":["x_refsource_MISC"],"url":"https://github.com/Graylog2/graylog2-server/commit/85dc699d6319aea433583dc239077a3a799c8627"},{"name":"https://github.com/Graylog2/graylog2-server/commit/d5051e604c962ef3d4e5e8e434d0ff4907d2140d","tags":["x_refsource_MISC"],"url":"https://github.com/Graylog2/graylog2-server/commit/d5051e604c962ef3d4e5e8e434d0ff4907d2140d"},{"name":"https://github.com/Graylog2/graylog2-server/commit/dde76d7432c469887d9a95c208083c5f0f73c70d","tags":["x_refsource_MISC"],"url":"https://github.com/Graylog2/graylog2-server/commit/dde76d7432c469887d9a95c208083c5f0f73c70d"}],"affected":[{"vendor":"Graylog2","product":"graylog2-server","versions":[{"version":"< 6.3.12","status":"affected"},{"version":">= 7.0.0-alpha.1, < 7.0.7","status":"affected"},{"version":">= 7.1.0-alpha.1, < 7.1.2","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-08-28T22:11:08.747Z"},"descriptions":[{"lang":"en","value":"Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and graylog2-server/src/main/java/org/graylog2/inputs/codecs/SyslogCodec.java mishandles field-like text inside quoted values. GLFortiGateSyslogEvent.getFields() uses KV_PATTERN and QUOTED_KV_PATTERN, while SyslogCodec.parse() invokes the FortiGateSyslogEvent parser; crafted values containing = or backslash-escaped quotes can cause embedded keys such as srcip, dstip, date, time, and tz to remove or overwrite original top-level fields or produce an invalid message that Graylog discards. An unauthenticated network sender who can submit syslog messages can therefore manipulate security-log fields or evade logging to obscure malicious activity. This issue is fixed in Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3."}],"source":{"advisory":"GHSA-gqr6-r77p-c2pj","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-01T02:02:52.990384Z","id":"CVE-2026-55841","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-01T02:03:04.137Z"}}]}}