Skip to content
Threat Feed
high advisory

Graylog Syslog Parser Vulnerability Enabling Log Evasion

A vulnerability in the Graylog syslog parser allows unauthenticated attackers to overwrite or discard logs from devices using key-value formats, such as Fortigate, facilitating log evasion.

CVE search metadata

CVE search record: CVE-2026-55841. Severity: high. CVSS: 7.5. KEV: no. Product: Graylog Server (v6.3.12, v7.0.7, v7.1.2). Brief: Graylog Syslog Parser Vulnerability Enabling Log Evasion. Brief link: https://feed.craftedsignal.io/briefs/2026-08-graylog-syslog-parsing-vulnerability/

A security vulnerability identified as CVE-2026-55841 affects the Graylog syslog parser when processing key-value formatted messages, notably those generated by Fortigate network appliances. This flaw allows an attacker to manipulate the incoming syslog stream to either overwrite critical message fields or intentionally create malformed messages. Because Graylog discards messages that fail parsing, this mechanism provides a direct method for log evasion, effectively blinding security operations teams to malicious activity occurring within the network environment. The issue is present across Graylog Server versions 6.x prior to 6.3.12, 7.0.x prior to 7.0.7, and 7.1.x prior to 7.1.2. Defenders relying on these versions for Fortigate log ingestion are at risk of having their audit trails suppressed by sophisticated actors attempting to mask their tracks.

Impact

The primary impact of this vulnerability is the loss of visibility into security events. By successfully triggering log parsing errors or field overwrites, an attacker can prevent security alerts from firing or remove evidence of lateral movement, persistence, or data exfiltration from the centralized logging repository. This allows attackers to operate within an environment while actively suppressing telemetry that would otherwise enable detection.

Recommendation

  • Upgrade Graylog Server immediately to versions 6.3.12, 7.0.7, or 7.1.2 to patch CVE-2026-55841.
  • Monitor the Indexing and Processing Failures Index in Graylog for a sudden spike in discarded messages, particularly those originating from Fortigate device sources.
  • Verify log integrity by correlating centralized Graylog logs with local logs stored on the Fortigate devices to identify potential gaps in coverage.

Immediate actions

Upgrade Graylog Server to versions 6.3.12, 7.0.7, or 7.1.2.

IT Operations 24h

Threat Hunt

Monitor for spikes in Indexing and Processing Failures originating from Fortigate log inputs.

T1562.001 high high confidence hunt now

Data: Graylog Processing Failures Index

Mitigations

Upgrade Graylog Server to 6.3.12 or later

immediate IT Operations

CVE-2026-55841