{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/logsign-siem-6.4.101-6.4.116/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:innotim:logsign_siem:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-90925"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Logsign SIEM (6.4.101 - 6.4.116)","Logsign SIEM (6.4.101-6.4.116)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","web-application"],"_cs_type":"advisory","_cs_vendors":["Innotim Software"],"content_html":"\u003cp\u003eInnotim Software's Logsign SIEM product is affected by a path traversal vulnerability identified as CVE-2026-90925. This vulnerability stems from improper validation of user-supplied input when accessing file paths, allowing an attacker to navigate outside of the intended directory structure. The flaw specifically impacts versions 6.4.101 through 6.4.116 of the Logsign SIEM platform. By manipulating file path parameters in HTTP requests, an unauthenticated user could potentially gain unauthorized read access to sensitive files stored on the server, including configuration files, credentials, or system logs. Defenders should prioritize patching affected instances to version 6.4.117 or later to mitigate the risk of information disclosure and potential system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized file access on the Logsign SIEM server. Depending on the files accessible, this could lead to the exposure of credentials, environment configurations, and other sensitive data, providing an attacker with sufficient reconnaissance to further compromise the network infrastructure where the SIEM is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Logsign SIEM to version 6.4.117 or later immediately to patch CVE-2026-90925.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous requests containing directory traversal sequences (e.g., \u0026quot;../\u0026quot;, \u0026quot;..%2f\u0026quot;) targeting non-public directories.\u003c/li\u003e\n\u003cli\u003eLimit network access to the Logsign SIEM web interface to trusted management networks only, using firewall controls to mitigate potential remote exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T16:21:02Z","date_published":"2026-09-28T16:20:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-logsign-path-traversal/","summary":"Logsign SIEM versions 6.4.101 through 6.4.116 are vulnerable to a path traversal flaw, CVE-2026-90925, which may allow an unauthenticated attacker to access unauthorized files on the host system.","title":"Path Traversal Vulnerability in Logsign SIEM","url":"https://feed.craftedsignal.io/briefs/2026-09-logsign-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Logsign SIEM (6.4.101-6.4.116)","version":"https://jsonfeed.org/version/1.1"}