Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.

This issue affects Logsign SIEM: before 6.4.115.
Published: 2026-07-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Logsign SIEM is an improper control of code generation, allowing an attacker to inject and execute arbitrary code without authentication. This code injection flaw, identified as CWE‑94, gives a remote attacker the ability to run any commands with the privileges of the SIEM process, compromising confidentiality, integrity, and availability of the entire SIEM deployment. The flaw affects all versions prior to 6.4.115.

Affected Systems

The affected product is Innotim Software's Logsign SIEM, specifically all releases before version 6.4.115. Users running older builds should identify their version and plan remediation.

Risk and Exploitability

With a CVSS base score of 9.8 the flaw is considered critical. The EPSS score of less than 1% indicates low current exploitation probability, and the lack of a KEV listing does not reduce the potential impact. Based on the description, it is inferred that an unauthenticated attacker can reach the vulnerable interface, likely via exposed management ports or web endpoints, and execute code directly on the host. Attackers need only network access to the SIEM and no specific user credential. Once exploited, arbitrary commands can be run or persistence installed.

Generated by OpenCVE AI on August 22, 2026 at 11:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Logsign SIEM to version 6.4.115 or later to remove the code injection flaw
  • Restrict network exposure of the SIEM management interface to trusted hosts or subnets, using firewall rules or VPN segmentation
  • Monitor the system for anomalous code execution or unauthorized changes after patching

Generated by OpenCVE AI on August 22, 2026 at 11:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108. Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115.

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Innotim
Innotim logsign Siem
Vendors & Products Innotim
Innotim logsign Siem

Fri, 31 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.
Title Unauthenticated RCE in Innotim Software's Logsign SIEM
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Innotim Logsign Siem
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-20T15:22:01.873Z

Reserved: 2026-07-27T14:24:08.230Z

Link: CVE-2026-17561

cve-icon Vulnrichment

Updated: 2026-07-31T19:54:30.788Z

cve-icon NVD

Status : Deferred

Published: 2026-07-31T13:17:19.730

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-17561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T11:15:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')