Skip to content
Threat Feed
critical advisory

Default Credential Vulnerability in Logsign SIEM

Logsign SIEM versions 6.4.101 through 6.4.116 contain a critical default credential vulnerability that permits unauthorized access via known usernames and passwords.

CVE search metadata

CVE search record: CVE-2026-90924. Severity: critical. CVSS: 9.8. KEV: no. Product: Logsign SIEM (6.4.101 to <6.4.117). Brief: Default Credential Vulnerability in Logsign SIEM. Brief link: https://feed.craftedsignal.io/briefs/2026-09-logsign-default-creds/

Logsign SIEM, developed by Innotim Software, Telecommunications and Consultancy Trade Ltd. Co., contains a critical vulnerability identified as CVE-2026-90924. This vulnerability arises from the use of default credentials within the application, allowing an attacker to bypass authentication mechanisms by leveraging common or default usernames and passwords. The scope of this issue affects product versions from 6.4.101 up to, but not including, 6.4.117. Given that SIEM platforms often ingest sensitive logs and hold administrative privileges across an organization's network, unauthorized access via this flaw could lead to full platform compromise, data exfiltration, or the tampering of security audit trails. Organizations running affected versions are at high risk of unauthenticated access by remote adversaries who identify the SIEM instance.

Impact

Successful exploitation of this vulnerability grants an attacker unauthorized administrative access to the Logsign SIEM interface. In a security operations context, this allows an adversary to view sensitive security telemetry, disable alerting, modify correlation rules, or gain pivot points into the broader internal infrastructure. As Logsign SIEM is a centralized repository for enterprise security data, compromise results in a loss of visibility and integrity for the entire SOC ecosystem.

Recommendation

Prioritize the immediate upgrade of all Logsign SIEM installations to version 6.4.117 or later to address CVE-2026-90924. If an immediate upgrade is not feasible, restrict network access to the SIEM management interface to authorized administrative segments only. Audit current user accounts for unauthorized modifications or unexpected login patterns from external IP addresses. Monitor web server logs for high-frequency login attempts directed at the SIEM administrative interface.


Immediate actions

Upgrade Logsign SIEM to version 6.4.117 or later

IT Operations 24h

Mitigations

Restrict access to the Logsign SIEM web interface to authorized management subnets only

immediate SOC

CVE-2026-90924