CVE-2026-90926
8.8 HIGHPublished 2026-09-28 · Updated 2026-09-28
AI risk analysis
- Summary
- A Code Injection vulnerability exists in Logsign SIEM versions from 6.4.101 before 6.4.117, allowing attackers to execute arbitrary code.
- Exploitability
- Exploitation is relatively straightforward given the code injection vulnerability, requiring an authenticated user with access to the affected version.
- Blast radius
- If exploited, this could lead to complete compromise of the system, including data exfiltration, system destruction, and unauthorized code execution.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Logsign SIEM version 6.4.117 or later.
rcecode-injectionweb
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-94
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-73369
- CRITICALCVE-2026-75703
- CRITICALCVE-2026-84412
- CRITICALCVE-2026-96754PoC
- CRITICALCVE-2026-96755PoC
- CRITICALCVE-2026-96758PoC
- HIGHCVE-2026-100856PoC
- HIGHCVE-2026-16623
Related by shared AI tags and CWE weakness class. Browse the full archive.