Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection.

This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
Published: 2026-09-28
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An input validation flaw in Logsign SIEM allows arbitrary code injection, granting attackers the ability to execute commands on the underlying host. This flaw enables compromise of confidentiality, integrity, and availability of the affected system and aligns with CWE‑94, Improper Control of Generation of Code.

Affected Systems

Logsign SIEM versions from 6.4.101 up to but not including 6.4.117 are impacted. The product is distributed by Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Users of these specific releases must assess whether they are running any vulnerable version.

Risk and Exploitability

The CVSS score of 8.8 marks it as a high‑severity risk. EPSS data are unavailable, and the lack of KEV listing does not eliminate the threat. Based on the description, it is inferred that attackers could deliver malicious payloads remotely through the Logsign SIEM application interface, representing the likely attack vector for code injection.

Generated by OpenCVE AI on September 28, 2026 at 16:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade Logsign SIEM to version 6.4.117 or later.
  • Restrict network access to the SIEM endpoints and enforce least‑privilege accounts to limit exposure.
  • Implement strict input validation and sanitization on all user‑controllable fields to prevent code injection; use whitelist validation rules.
  • Monitor SIEM logs for signs of injected code or anomalous activity.

Generated by OpenCVE AI on September 28, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Innotim Software Telecommunications And Consulting Trade Ltd. Co.
Innotim Software Telecommunications And Consulting Trade Ltd. Co. logsign Siem
Vendors & Products Innotim Software Telecommunications And Consulting Trade Ltd. Co.
Innotim Software Telecommunications And Consulting Trade Ltd. Co. logsign Siem

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
Title Code Injection in Innotim Software's Logsign SIEM
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Innotim Software Telecommunications And Consulting Trade Ltd. Co. Logsign Siem
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-28T16:32:28.001Z

Reserved: 2026-09-14T11:26:50.253Z

Link: CVE-2026-90926

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:26.956Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:21.993

Modified: 2026-09-28T17:17:52.550

Link: CVE-2026-90926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:15:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')