Skip to content
CVE-2026-90925 and CVE-2026-90926 Affect Innotim Logsign SIEM

CVE-2026-90925 and CVE-2026-90926 Affect Innotim Logsign SIEM

First seen 28 Sep 2026, 17:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 18:20 UTC
  • •Two vulnerabilities in Logsign SIEM: CVE-2026-90925 and CVE-2026-90926.
  • •Both CVEs affect versions 6.4.101 to 6.4.116 and were published on 2026-09-28.
  • •Immediate upgrade to patched versions is recommended to mitigate risks.

Innotim Software's Logsign SIEM has two critical vulnerabilities: CVE-2026-90925 (Path Traversal) and CVE-2026-90926 (Code Injection). Both vulnerabilities affect versions 6.4.101 to 6.4.116 and were published on 2026-09-28. CVE-2026-90925 allows attackers to alter files or resources, potentially disrupting monitoring and investigations. CVE-2026-90926 enables code execution, which could tamper with security data and expose sensitive logs. Both vulnerabilities require low-level privileges for exploitation, making deployments accessible from the internet particularly at risk. Urgency is noted but cannot be elevated due to lack of exploitation evidence. Organizations are advised to upgrade to the fixed release and restrict access until patched.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
CVE-2026-90925 and CVE-2026-90926 published
Innotim Software disclosed vulnerabilities affecting Logsign SIEM versions 6.4.101 to 6.4.116.
Redpacketsecurity
2026-09-28
Risk assessment issued
Both vulnerabilities assessed with urgency but no confirmed exploitation evidence provided.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Logsign and CVE-2026-90925 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed