Graylog Syslog Parser Vulnerability Enabling Log Evasion
A vulnerability in the Graylog syslog parser allows unauthenticated attackers to overwrite or discard logs from devices using key-value formats, such as Fortigate, facilitating log evasion.
CVE search metadata
CVE search record: CVE-2026-55841. Severity: high. CVSS: 7.5. KEV: no. Product: Graylog Server (v6.3.12, v7.0.7, v7.1.2). Brief: Graylog Syslog Parser Vulnerability Enabling Log Evasion. Brief link: https://feed.craftedsignal.io/briefs/2026-08-graylog-syslog-parsing-vulnerability/
A security vulnerability identified as CVE-2026-55841 affects the Graylog syslog parser when processing key-value formatted messages, notably those generated by Fortigate network appliances. This flaw allows an attacker to manipulate the incoming syslog stream to either overwrite critical message fields or intentionally create malformed messages. Because Graylog discards messages that fail parsing, this mechanism provides a direct method for log evasion, effectively blinding security operations teams to malicious activity occurring within the network environment. The issue is present across Graylog Server versions 6.x prior to 6.3.12, 7.0.x prior to 7.0.7, and 7.1.x prior to 7.1.2. Defenders relying on these versions for Fortigate log ingestion are at risk of having their audit trails suppressed by sophisticated actors attempting to mask their tracks.
Impact
The primary impact of this vulnerability is the loss of visibility into security events. By successfully triggering log parsing errors or field overwrites, an attacker can prevent security alerts from firing or remove evidence of lateral movement, persistence, or data exfiltration from the centralized logging repository. This allows attackers to operate within an environment while actively suppressing telemetry that would otherwise enable detection.
Recommendation
- Upgrade Graylog Server immediately to versions 6.3.12, 7.0.7, or 7.1.2 to patch CVE-2026-55841.
- Monitor the Indexing and Processing Failures Index in Graylog for a sudden spike in discarded messages, particularly those originating from Fortigate device sources.
- Verify log integrity by correlating centralized Graylog logs with local logs stored on the Fortigate devices to identify potential gaps in coverage.
Immediate actions
Upgrade Graylog Server to versions 6.3.12, 7.0.7, or 7.1.2.
Threat Hunt
Monitor for spikes in Indexing and Processing Failures originating from Fortigate log inputs.
Data: Graylog Processing Failures Index
Mitigations
Upgrade Graylog Server to 6.3.12 or later
CVE-2026-55841