Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or leaked 'sessionId' can continue to be used to authenticate valid requests. Exploiting this vulnerability would allow an attacker with access to the web service/API network (port 9000 or HTTP/S endpoint of the server) to reuse an old session token to gain unauthorized access to the application, interact with the API/web, and compromise the integrity of the affected account.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Graylog graylog
|
|
| CPEs | cpe:2.3:a:graylog:graylog:2.2.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Graylog graylog
|
|
| Metrics |
cvssV3_1
|
Wed, 18 Feb 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, which remain valid even after multiple consecutive logins by the same user. As a result, a stolen or leaked 'sessionId' can continue to be used to authenticate valid requests. Exploiting this vulnerability would allow an attacker with access to the web service/API network (port 9000 or HTTP/S endpoint of the server) to reuse an old session token to gain unauthorized access to the application, interact with the API/web, and compromise the integrity of the affected account. | |
| Title | Incorrect management of session invalidation vulnerability in Graylog Web Interface | |
| First Time appeared |
Graylog
Graylog graylog Web Interface |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:graylog:graylog_web_interface:2.2.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Graylog
Graylog graylog Web Interface |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2026-02-18T13:08:36.348Z
Updated: 2026-02-18T20:24:40.349Z
Reserved: 2026-01-26T13:20:06.891Z
Link: CVE-2026-1435
Updated: 2026-02-18T20:24:28.278Z
Status : Analyzed
Published: 2026-02-18T14:16:05.700
Modified: 2026-02-18T20:22:51.750
Link: CVE-2026-1435
No data.