Insufficiently Protected Credentials in Logsign SIEM
Logsign SIEM versions 6.4.97 through 6.4.113 are vulnerable to an insufficiently protected credentials flaw, allowing privileged users to retrieve embedded sensitive data (CVE-2026-14564).
CVE search metadata
CVE search record: CVE-2026-14564. Severity: critical. CVSS: 9.0. KEV: no. Product: Logsign SIEM (6.4). Brief: Insufficiently Protected Credentials in Logsign SIEM. Brief link: https://feed.craftedsignal.io/briefs/2026-08-logsign-siem-credentials/
CVE-2026-14564 describes a vulnerability in Innotim Software's Logsign SIEM product, specifically affecting versions 6.4.97 up to, but not including, 6.4.114. The flaw is categorized as an Insufficiently Protected Credentials issue (CWE-522). This vulnerability allows an authenticated attacker with administrative privileges to retrieve sensitive data embedded within the application. Given the nature of a SIEM, which centralizes logs, security alerts, and often credentials for managed assets, the ability to extract embedded secrets represents a critical risk to the broader security ecosystem. Organizations running affected versions are urged to upgrade to version 6.4.114 or later to remediate the exposure.
Impact
Successful exploitation of this vulnerability enables an attacker with elevated access to bypass security controls and gain unauthorized access to sensitive information stored or processed by the SIEM. This potentially facilitates lateral movement, credential theft, and access to integrated infrastructure monitoring data, which could impact the entire network environment.
Recommendation
- Upgrade all Logsign SIEM instances to version 6.4.114 or later to address CVE-2026-14564.
- Audit logs for the period prior to patching to identify any anomalous access to sensitive system configurations or configuration export events.
- Review administrative access logs for unusual user activity associated with the affected product.
Immediate actions
Upgrade Logsign SIEM to version 6.4.114.
Mitigations
Restrict administrative access to Logsign SIEM to trusted networks only.
CVE-2026-14564