Sceawere

Vulnerability Detail

CVE-2026-90924UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Logsign SIEM Default Credential Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Innotim Software, Telecommunications and Consultan…
Product
Logsign SIEM
Attack Type
CWE-1392 Use of default credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-28T14:17:21.720Z",
  "pubdate": "2026-09-28T14:17:21.720Z",
  "executiveSummary": "This vulnerability involves the presence of default authentication credentials within the Logsign SIEM platform, classified under the category of using default usernames and passwords.\nThe issue affects Logsign SIEM versions ranging from 6.4.101 up to, but not including, 6.4.117.\nThe primary risk implication is unauthorized access to sensitive security information and event management capabilities, potentially allowing an attacker to gain full administrative control over the security monitoring infrastructure.\nThe vulnerability requires minimal attacker capability, as it relies on the known default credentials being present and unchanged. Successful exploitation allows for unauthorized authentication, which can lead to data exfiltration, configuration tampering, and the compromise of ingested security logs, effectively bypassing the security monitoring controls the product is intended to provide.",
  "technicalDetails": "The vulnerability stems from the inclusion of hardcoded or default credentials within the Logsign SIEM appliance deployment, which remain active upon initial configuration unless explicitly modified by the administrator.\nThe affected component is the authentication mechanism responsible for securing administrative access to the Logsign SIEM management interface. By failing to enforce a password change policy upon initial setup or by utilizing pre-configured account credentials for system-level access, the system exposes a critical security control to trivial bypass.\nThe attack flow commences with the threat actor identifying a target instance of the vulnerable Logsign SIEM software. Because the credentials are 'common' or 'default', an attacker does not need to perform complex reconnaissance or exploit memory corruption bugs; rather, they perform a standard authentication attempt using the known default username and password pair.\nIf the administrative interface is accessible via the network, the attacker provides these credentials to the login portal. Upon successful validation by the backend authentication service, the system grants the attacker a session token associated with a high-privilege account. This effectively bypasses the intended security posture, allowing the actor to establish a persistent, authenticated foothold.\nOnce access is achieved, the post-exploitation impact is severe. Since Logsign SIEM acts as a central repository for logs across the corporate infrastructure, an authenticated attacker can perform several malicious actions. These include, but are not limited to, disabling alert triggers to mask malicious activity, modifying log retention policies to delete evidence of intrusion, or reconfiguring the system to forward logs to external unauthorized endpoints. The attacker effectively gains complete visibility into the monitored environment's security posture and the ability to manipulate the veracity of security telemetry, undermining the integrity of the entire incident response process.\nThis vulnerability is present in Logsign SIEM versions 6.4.101 through 6.4.116. Versions 6.4.117 and later are designed to address this security oversight."
}
CVE-2026-90924: Logsign SIEM Default Credential Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere