CVE-2026-14564
9.0Innotim Software Telecommunications and Consulting Trade Ltd. · Logsign SIEM
A vulnerability exists in Logsign SIEM involving insufficiently protected credentials, which allows an authenticated attacker with high privileges to retrieve sensitive embedded data.
Executive summary
An insufficiently protected credentials vulnerability in Logsign SIEM allows high-privileged users to extract sensitive data, posing a critical security risk to system integrity.
Vulnerability
This is an Insufficiently Protected Credentials vulnerability (CWE-522) that allows an attacker with high privileges to access sensitive information. The attack vector is network-based, but it requires an attacker to already possess administrative or high-level credentials to exploit the flaw.
Business impact
The ability to retrieve sensitive embedded data from a Security Information and Event Management (SIEM) system is a high-impact event. Given the CVSS score of 9.0, this vulnerability could allow an attacker to obtain credentials or configuration data, leading to lateral movement, further unauthorized access to integrated systems, and potential compromise of the entire security monitoring infrastructure.
Remediation
Immediate Action: Update Logsign SIEM to version 6.4.114 or later immediately to address the credential protection flaw.
Proactive Monitoring: Review administrative access logs for unusual queries or bulk data retrieval actions performed by high-privileged accounts.
Compensating Controls: Ensure that access to the SIEM management console is restricted to trusted networks and that multi-factor authentication is strictly enforced for all administrative sessions.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant risk to the confidentiality of sensitive system data. Administrators should prioritize the update to version 6.4.114 to rectify this weakness. Given the critical nature of SIEM platforms in an organization's security posture, patching should be scheduled as a high-priority task.