Skip to content
CVE Alert: CVE-2026-90925 – Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.

CVE Alert: CVE-2026-90925 – Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.

Redpacketsecurity •admin • September 28, 2026

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

**Risk verdict:** Treat as a meaningful integrity risk, but urgency cannot be elevated on exploitation evidence because KEV, SSVC, PoC and EPSS data were not provided.

**Why this matters:** A successful attack could let an intruder alter files or resources accessible to the SIEM service, potentially weakening monitoring, corrupting detection content or disrupting operations. Tampering with logs or rules could also delay investigations and conceal activity elsewhere in the environment.

**Most likely attack path:** The network-accessible flaw has low complexity and requires limited privileges, but no user action; exposure therefore depends on an attacker obtaining an account or equivalent access. Scope is unchanged, so there is no indicated direct impact beyond the vulnerable security authority, though altered SIEM data could undermine visibility across connected systems.

**Who is most exposed:** Prioritise deployments reachable from the internet or broad user networks, especially central SIEM instances receiving logs from many systems. Internal-only access reduces opportunity but does not remove risk from compromised accounts.

Review web and application logs for traversal sequences, encoded path variants and unusual file-related requests.

Alert on unexpected writes or permission changes to SIEM configuration, detection rules and log-processing files.

Check for unusual low-privilege accounts, sessions or source addresses accessing the management interface.

Validate recent SIEM rule changes and investigate gaps or anomalies in log ingestion.

Mitigation and prioritisation:

Upgrade promptly to the vendor-fixed release or later; verify the installed build and successful restart.

Until patched, restrict management access to trusted administration networks and block unneeded routes.

Run the service with least privilege; review file permissions and preserve known-good configuration backups.

Apply through change control, then validate detections, log ingestion and configuration integrity.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

CWE Weaknesses (1)

Platforms (1)

Vulnerabilities (1)