CVE-2026-17561
Innotim Software · Logsign SIEM
A code injection vulnerability in Logsign SIEM allows unauthenticated attackers to execute arbitrary code due to improper control of code generation.
Executive summary
Logsign SIEM contains a critical code injection vulnerability that allows unauthenticated remote attackers to gain full system control.
Vulnerability
This is a code injection flaw (CWE-94) stemming from improper control of code generation. The vulnerability is exploitable over the network by an unauthenticated attacker, requiring no user interaction.
Business impact
Successful exploitation of this vulnerability leads to complete system compromise, allowing an attacker to execute arbitrary commands with the privileges of the application. Given the critical CVSS score of 9.8, this poses an extreme risk to data confidentiality, integrity, and availability, potentially exposing sensitive security logs and administrative credentials managed by the SIEM.
Remediation
Immediate Action: Update Logsign SIEM to version 6.4.108 or later immediately to resolve the injection flaw.
Proactive Monitoring: Review system access logs for unusual command execution patterns or unauthorized requests directed at the SIEM management interface.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block malicious code injection payloads targeting backend application logic.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability cannot be overstated, as it provides an unauthenticated path to total system compromise. Organizations running Logsign SIEM must prioritize the upgrade to version 6.4.108 as their primary security objective to neutralize this critical risk.