Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.

This issue affects Logsign SIEM: before 6.4.115.
Published: 2026-07-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Logsign SIEM arises from improper control over code generation, allowing an attacker to inject and execute arbitrary code. This flaw, classified as CWE‑94, enables full remote code execution without authentication, meaning any user able to reach the affected component can run arbitrary commands with the privileges of the SIEM process. The result is a compromise of confidentiality, integrity, and availability, potentially giving control of the entire SIEM deployment. The vulnerability is reported as affecting all versions prior to 6.4.108.

Affected Systems

The affected product is Innotim Software's Logsign SIEM, specifically all releases before version 6.4.108. Users running older builds should identify their version and plan remediation.

Risk and Exploitability

With a CVSS base score of 9.8 the flaw is considered critical. The EPSS score of less than 1% indicates low current exploitation probability, but the lack of prior KEV listing does not diminish the potential impact. The best‑practice assessment is that an unauthenticated attacker can reach the vulnerable interface, likely via exposed management ports or web endpoints, and execute code directly on the host. Attackers need network access to the SIEM and no specific user credential. Once exploited, the attacker can execute arbitrary commands or install persistence mechanisms.

Generated by OpenCVE AI on August 2, 2026 at 04:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Logsign SIEM to version 6.4.108 or later to remove the code injection flaw
  • Restrict network exposure of the SIEM management interface to trusted hosts or subnets, using firewall rules or VPN segmentation
  • Monitor the system for anomalous code execution or unauthorized changes after patching

Generated by OpenCVE AI on August 2, 2026 at 04:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108. Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115.

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Innotim
Innotim logsign Siem
Vendors & Products Innotim
Innotim logsign Siem

Fri, 31 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.
Title Unauthenticated RCE in Innotim Software's Logsign SIEM
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Innotim Logsign Siem
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-20T15:22:01.873Z

Reserved: 2026-07-27T14:24:08.230Z

Link: CVE-2026-17561

cve-icon Vulnrichment

Updated: 2026-07-31T19:54:30.788Z

cve-icon NVD

Status : Received

Published: 2026-07-31T13:17:19.730

Modified: 2026-08-20T16:17:17.050

Link: CVE-2026-17561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:48Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')