Junglewise Threat Intelligence

CVE-2026-17561: Innotim Logsign SIEM code injection

CVE-2026-17561 · Severity: critical · CVSS 9.8 · Published 2026-07-31

Executive brief

Logsign SIEM is a security management platform used by organizations to monitor and analyze security events across their networks. A critical vulnerability has been identified that allows remote attackers to inject and execute malicious code on the system without needing any login credentials. This could lead to a complete takeover of the security platform, allowing attackers to steal sensitive data, disrupt security monitoring, or use the system as a foothold to attack other parts of the corporate network.

Technical details

A code injection vulnerability (CWE-94) exists in Innotim Logsign SIEM due to improper control of code generation. The flaw allows a remote, unauthenticated attacker to send specially crafted requests over the network to execute arbitrary code on the underlying operating system. The vulnerability is rated with a CVSS score of 9.8, reflecting its low complexity and lack of required privileges or user interaction. The issue is resolved in Logsign SIEM version 6.4.108.

Affected products

  • Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM before 6.4.108

Timeline

  • 2026-07-31: disclosed
  • 2026-07-31: advisory

References