Sceawere

Vulnerability Detail

CVE-2026-90926UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Logsign SIEM Code Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Innotim Software, Telecommunications and Consultan…
Product
Logsign SIEM
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-28T14:17:21.993Z",
  "pubdate": "2026-09-28T14:17:21.993Z",
  "executiveSummary": "Logsign SIEM is susceptible to an Improper Control of Generation of Code vulnerability, classified as Code Injection. This security flaw allows an authenticated or unauthenticated attacker, depending on the entry point, to inject and execute arbitrary code within the context of the application's runtime environment.\nThe vulnerability exists in Logsign SIEM versions ranging from 6.4.101 to 6.4.116. If successfully exploited, this vulnerability could allow an attacker to bypass security controls, gain unauthorized access to sensitive system data, manipulate logs, or achieve full system compromise by executing malicious commands with the privileges of the underlying service account.\nThe risk implication is critical, as it compromises the integrity and confidentiality of the SIEM platform, which is intended to serve as a central security oversight tool. Organizations should prioritize updating to version 6.4.117 or later to remediate the underlying flaw.",
  "technicalDetails": "The vulnerability is categorized as CWE-94: Improper Control of Generation of Code ('Code Injection'). This issue arises when the Logsign SIEM application improperly sanitizes user-supplied input before passing it to an interpreter or a code-generation function. The root cause lies in the application's failure to adequately validate or encode external data that influences the construction of command strings or internal executable scripts.\nThe attack flow typically involves an attacker identifying a vulnerable input vector within the Logsign SIEM web interface or API that processes data without sufficient validation. By injecting specially crafted payloads—such as shell metacharacters, scripting syntax, or language-specific delimiters—the attacker can alter the intended execution logic of the application. Upon processing the malicious input, the application interprets the injected segments as valid code or commands.\nBecause Logsign SIEM operates as a security monitoring tool, it frequently runs with elevated privileges to interface with system logs, network traffic, and database repositories. Consequently, the successful execution of injected code grants the attacker the same operational permissions as the service process. This allows for post-exploitation activities such as executing system-level commands, installing persistence mechanisms (e.g., webshells), or exfiltrating logs and configuration files containing sensitive credentials or network architecture details.\nAffected versions include the continuous range from 6.4.101 up to, but not including, 6.4.117. The vulnerability is tied to the internal handling of parameters that fail to adhere to strict whitelist-based validation or parameterized execution patterns. Exposure is generally limited to network-accessible instances of the Logsign SIEM interface, where attackers can reach the vulnerable entry points via standard HTTP/HTTPS protocols. No complex social engineering is necessarily required, as the vulnerability resides in the application's processing logic, making it exploitable as long as the attacker has network connectivity to the target service and the ability to interact with the affected input fields."
}
CVE-2026-90926: Logsign SIEM Code Injection Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere