Sceawere

Vulnerability Detail

CVE-2026-14564UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Logsign SIEM Credential Disclosure Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9
Creation Date
8h ago
Vendor
Innotim Software Telecommunications and Consulting…
Product
Logsign SIEM
Attack Type
CWE-522 Insufficiently Protected Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.0",
  "pubDate": "2026-08-17T13:16:50.797Z",
  "pubdate": "2026-08-17T13:16:50.797Z",
  "executiveSummary": "An insufficiently protected credentials vulnerability exists in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM, specifically classified as Retrieve Embedded Sensitive Data.\nThis security flaw impacts Logsign SIEM versions ranging from 6.4.97 prior to 6.4.114.\nThe vulnerability allows unauthorized actors to extract sensitive embedded credentials due to inadequate protection mechanisms within the application architecture.\nSuccessful exploitation of this issue can lead to the exposure of confidential authentication materials, potentially facilitating unauthorized access to underlying systems, lateral movement within the network, and compromise of sensitive security information and event management infrastructure.\nThe risk implication is severe, as SIEM platforms typically centralize critical enterprise logs and credentials, making compromised data extremely valuable for subsequent adversarial operations.\nThreat actors possessing network access to the vulnerable application components may leverage this flaw to retrieve sensitive data without requiring prior high-privileged authentication, depending on the specific exposure vectors of the affected versions.",
  "technicalDetails": "The vulnerability resides within Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM, specifically affecting versions from 6.4.97 up to, but not including, 6.4.114.\nThe root cause of the issue stems from the insufficient protection and improper handling of embedded sensitive data and credentials within the application components.\nWhen deployed, the affected software improperly secures internal credentials, allowing unauthorized retrieval through accessible endpoints or insecure storage mechanisms.\nThe attack flow generally involves an adversary identifying the vulnerable component within the Logsign SIEM deployment where sensitive data is stored or processed.\nUpon locating the target component, the attacker interacts with the system via available network interfaces or API endpoints to extract the improperly protected credentials.\nBecause the application fails to enforce strict access controls or cryptographic obfuscation on the sensitive data, the embedded credentials can be parsed and retrieved in plaintext or reversibly encoded formats.\nThe exploitation method relies on querying or accessing the vulnerable data storage or transmission channels exposed by the application.\nAuthentication and privilege requirements depend on the exact exposure surface, but the vulnerability permits the retrieval of sensitive data that should otherwise be restricted to authorized administrative contexts.\nNetwork exposure is a contributing factor, as attackers require network reachability to the Logsign SIEM instance to interact with the vulnerable features.\nFollowing successful exploitation and credential extraction, post-exploitation impact includes the reuse of harvested credentials to authenticate against integrated services, databases, or management interfaces, potentially leading to full administrative compromise of the SIEM solution and integrated enterprise environments."
}
CVE-2026-14564: Logsign SIEM Credential Disclosure Vulnerability (CRITICAL Severity, CVSS: 9.0) - Sceawere