Back Redpacketsecurity CVE Alert: CVE-2026-90926 – Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.
Improper Control of Generation of Code (‘Code Injection’) vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
**Risk verdict:** Treat reachable deployments as high priority; KEV, SSVC, PoC and EPSS status are not provided, so active exploitation and its prevalence remain unconfirmed.
**Why this matters:** Code execution in a SIEM could let an attacker tamper with security data, weaken detections, expose sensitive logs or disrupt monitoring. That can delay response to other intrusions and reduce confidence in the organisation’s security evidence.
**Most likely attack path:** The network-reachable, low-complexity path requires low-level privileges but no further user action. An attacker would therefore likely need a valid low-privilege account or equivalent access first; the stated unchanged scope suggests direct impact remains within the affected security platform’s authority boundary, although connected systems may widen consequences.
**Who is most exposed:** Organisations running affected deployments, particularly where administration or user access is reachable from the internet, broad internal networks or third parties. SIEMs with extensive integrations and privileged service accounts warrant particular scrutiny.
Review authentication and application logs for unusual low-privilege account activity.
Look for unexpected child processes or command execution by SIEM services.
Check for unauthorised changes to rules, integrations, configuration or stored logs.
Investigate unusual outbound connections from the SIEM host.
Mitigation and prioritisation
Upgrade promptly to the vendor’s fixed release; confirm the deployed build is outside the affected range.
Until patched, restrict access to trusted management networks and remove unnecessary accounts.
Review SIEM integrity and connected service-account permissions; rotate credentials if compromise is suspected.
Schedule the change through emergency change control, then validate detections and integrations.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
