← Back to search

CVE-2026-90926

8.8 HIGH

Published 2026-09-28 · Updated 2026-09-28

AI risk analysis

Summary
A Code Injection vulnerability exists in Logsign SIEM versions from 6.4.101 before 6.4.117, allowing attackers to execute arbitrary code.
Exploitability
Exploitation is relatively straightforward given the code injection vulnerability, requiring an authenticated user with access to the affected version.
Blast radius
If exploited, this could lead to complete compromise of the system, including data exfiltration, system destruction, and unauthorized code execution.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Logsign SIEM version 6.4.117 or later.
rcecode-injectionweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.