CVE-2026-55841CWE-138

CVE-2026-55841

High · published August 29, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
28.5
In the wild
Unconfirmed
What it is

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and graylog2-server/src/main/java/org/graylog2/inputs/codecs/SyslogCodec.java mishandles field-like text inside quoted values. GLFortiGateSyslogEvent.getFields() uses KV_PATTERN and QUOTED_KV_PATTERN, while SyslogCodec.parse() invokes the FortiGateSyslogEvent parser; crafted values containing = or backslash-escaped quotes can cause embedded keys such as srcip, dstip, date, time, and tz to remove or overwrite original top-level fields or produce an invalid message that Graylog discards. An unauthenticated network sender who can submit syslog messages can therefore manipulate security-log fields or evade logging to obscure malicious activity. This issue is fixed in Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00355 · 28.5th percentile
Weakness
CWE-138 · Improper Neutralization of Special Elements
Published
2026-08-29T03:17Z
References (9)
EPSS history
Timeline
  • 30 AUG 16:18Z
    EPSS moved — → 0%
    epss
  • 28 AUG 22:11Z
    Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message
    cvelistv5