<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Logsign SIEM (6.4.101-6.4.116) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/logsign-siem-6.4.101-6.4.116/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 16:20:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/logsign-siem-6.4.101-6.4.116/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Logsign SIEM</title><link>https://feed.craftedsignal.io/briefs/2026-09-logsign-path-traversal/</link><pubDate>Mon, 28 Sep 2026 16:20:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-logsign-path-traversal/</guid><description>Logsign SIEM versions 6.4.101 through 6.4.116 are vulnerable to a path traversal flaw, CVE-2026-90925, which may allow an unauthenticated attacker to access unauthorized files on the host system.</description><content:encoded><![CDATA[<p>Innotim Software's Logsign SIEM product is affected by a path traversal vulnerability identified as CVE-2026-90925. This vulnerability stems from improper validation of user-supplied input when accessing file paths, allowing an attacker to navigate outside of the intended directory structure. The flaw specifically impacts versions 6.4.101 through 6.4.116 of the Logsign SIEM platform. By manipulating file path parameters in HTTP requests, an unauthenticated user could potentially gain unauthorized read access to sensitive files stored on the server, including configuration files, credentials, or system logs. Defenders should prioritize patching affected instances to version 6.4.117 or later to mitigate the risk of information disclosure and potential system compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized file access on the Logsign SIEM server. Depending on the files accessible, this could lead to the exposure of credentials, environment configurations, and other sensitive data, providing an attacker with sufficient reconnaissance to further compromise the network infrastructure where the SIEM is deployed.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Logsign SIEM to version 6.4.117 or later immediately to patch CVE-2026-90925.</li>
<li>Review web server access logs for anomalous requests containing directory traversal sequences (e.g., &quot;../&quot;, &quot;..%2f&quot;) targeting non-public directories.</li>
<li>Limit network access to the Logsign SIEM web interface to trusted management networks only, using firewall controls to mitigate potential remote exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>path-traversal</category><category>web-application</category></item></channel></rss>