What is CVE-2026-65011?
Graylog2 Server before commit 46a2eeb has a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint, allowing authenticated users with the eventdefinitions:create capability to clone any private event definition. This poses a risk of sensitive information disclosure, and updating to the patched commit is recommended.
Azərbaycanca: Graylog2 Server-də POST /events/definitions/{definitionId}/duplicate endpoint-də per-entity icazə yoxlanışının çatışmazlığı, autentifikasiya olunmuş aşağı səlahiyyətli istifadəçilərə istənilən özəl event definition-ı klonlamağa imkan verir. Bu, həssas məlumatların oxunmasına səbəb ola bilər, serveri commit 46a2eeb-ə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What vulnerability in Graylog2 Server allows low-privileged users to clone private event definitions?
Graylog2 Server before commit 46a2eeb has a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint.
What risk can an authenticated user exploiting CVE-2026-65011 cause?
This vulnerability poses a risk of sensitive information disclosure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.