Sceawere

Vulnerability Detail

CVE-2026-90925UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Logsign SIEM Path Traversal Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Innotim Software, Telecommunications and Consultan…
Product
Logsign SIEM
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-28T14:17:21.863Z",
  "pubdate": "2026-09-28T14:17:21.863Z",
  "executiveSummary": "This vulnerability is categorized as Improper Limitation of a Pathname to a Restricted Directory, commonly known as Path Traversal (CWE-22).\nIt affects Logsign SIEM versions 6.4.101 through 6.4.116.\nThe flaw permits an unauthorized actor to manipulate file path references, potentially resulting in unauthorized access to sensitive system files, configuration data, or internal directories outside the intended web root or application scope.\nThe risk implication is significant as it may allow for information disclosure, potentially exposing system credentials, environment variables, or sensitive log data stored on the underlying server.\nExploitation requires the attacker to send specially crafted requests containing directory traversal sequences (e.g., ../) to the affected application endpoints.\nSuccessful exploitation compromises the confidentiality and integrity of the application environment by bypassing intended directory restrictions enforced by the web application or service.",
  "technicalDetails": "The vulnerability resides within the file handling mechanisms of Logsign SIEM, where user-supplied input is utilized to construct file system paths without sufficient sanitization or validation.\nThe root cause is the failure of the application to properly sanitize and filter path traversal sequences, such as '../' or '..\\', before processing requests involving file system operations.\nIn a typical attack flow, an attacker identifies a parameter or request URI that interacts with the file system. By injecting dot-dot-slash (../) sequences into this input, the attacker can traverse outside the designated directory structure.\nFor example, if the application serves files from /var/www/html/assets/, a malicious request such as GET /assets/../../../../etc/passwd could force the application to traverse to the root directory and retrieve sensitive system configuration files.\nThis vulnerability is particularly dangerous as it operates at the application layer, potentially allowing access to files that the SIEM service account has permissions to read, even if those files are not intended for public access.\nThe flaw affects Logsign SIEM versions from 6.4.101 up to 6.4.117 (exclusive). Systems running these versions are susceptible to arbitrary file read attacks provided the attacker has network access to the target endpoint.\nAuthentication and privilege requirements depend on the specific endpoint exposed; if the traversal point is accessible via an unauthenticated or public-facing endpoint, the threat level increases significantly.\nPost-exploitation, an attacker can leverage the access to read system files to perform reconnaissance, extract sensitive configuration parameters, steal session tokens or application secrets, and gather information necessary to facilitate further lateral movement or escalation within the infrastructure.\nThe behavior of the payload is to trick the server-side file API into interpreting the path traversal sequences as navigation commands, effectively breaking out of the application's 'jail' or restricted sandbox directory.\nLack of proper input validation, path normalization, and use of absolute versus relative paths are primary contributors to the persistence of this flaw in the affected software versions."
}
CVE-2026-90925: Logsign SIEM Path Traversal Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere