# CVE-2026-55841

## Summary

- **CVE ID:** CVE-2026-55841
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
- **CWE:** CWE-138
- **Published:** Aug 28, 2026
- **Last Modified:** Sep 1, 2026

## Description

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and graylog2-server/src/main/java/org/graylog2/inputs/codecs/SyslogCodec.java mishandles field-like text inside quoted values. GLFortiGateSyslogEvent.getFields() uses KV_PATTERN and QUOTED_KV_PATTERN, while SyslogCodec.parse() invokes the FortiGateSyslogEvent parser; crafted values containing = or backslash-escaped quotes can cause embedded keys such as srcip, dstip, date, time, and tz to remove or overwrite original top-level fields or produce an invalid message that Graylog discards. An unauthenticated network sender who can submit syslog messages can therefore manipulate security-log fields or evade logging to obscure malicious activity. This issue is fixed in Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3.

## Affected Products

- Graylog2 — graylog2-server (< 6.3.12)
- Graylog2 — graylog2-server (>= 7.0.0-alpha.1, < 7.0.7)
- Graylog2 — graylog2-server (>= 7.1.0-alpha.1, < 7.1.2)

## References

- [CNA](https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-gqr6-r77p-c2pj)
- [CNA](https://github.com/Graylog2/graylog2-server/pull/26050)
- [CNA](https://github.com/Graylog2/graylog2-server/pull/26056)
- [CNA](https://github.com/Graylog2/graylog2-server/pull/26057)
- [CNA](https://github.com/Graylog2/graylog2-server/pull/26059)
- [CNA](https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8a775961dd3f)
- [CNA](https://github.com/Graylog2/graylog2-server/commit/85dc699d6319aea433583dc239077a3a799c8627)
- [CNA](https://github.com/Graylog2/graylog2-server/commit/d5051e604c962ef3d4e5e8e434d0ff4907d2140d)
- [CNA](https://github.com/Graylog2/graylog2-server/commit/dde76d7432c469887d9a95c208083c5f0f73c70d)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.36%
- **EPSS Percentile:** 28.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._