{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/innotim-software-telecommunications-and-consulting-trade-ltd.-co./feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-17561"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Logsign SIEM"],"_cs_severities":["critical"],"_cs_tags":["code-injection","rce","siem","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Innotim Software, Telecommunications and Consulting Trade Ltd. Co."],"content_html":"\u003cp\u003eA critical code injection vulnerability (CVE-2026-17561) exists in Logsign SIEM versions earlier than 6.4.108. The vulnerability, classified as CWE-94: Improper Control of Generation of Code, allows an unauthenticated remote attacker to inject and execute arbitrary code on the affected appliance. This flaw stems from a lack of proper validation or sanitization during code generation processes within the SIEM architecture.\u003c/p\u003e\n\u003cp\u003eGiven the central role of a SIEM in an organization's security infrastructure, the ability for an attacker to gain unauthenticated remote code execution (RCE) represents a significant threat. Successful exploitation could lead to full system compromise, exfiltration of sensitive security logs, or the manipulation of security alerts to hide malicious activity within the target network.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 9.8, reflecting its critical severity. It requires no authentication and utilizes a low-complexity attack vector, making it an attractive target for external threat actors. Organizations using Logsign SIEM are at risk of complete platform takeover, potentially leading to unauthorized data access, lateral movement, or the permanent impairment of security monitoring capabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Logsign SIEM to version 6.4.108 or higher immediately to remediate the vulnerability identified by CVE-2026-17561.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Logsign SIEM management interface to authorized administrative segments only, ensuring it is not exposed to the public internet.\u003c/li\u003e\n\u003cli\u003eReview audit logs for anomalous process creation, unexpected outbound network connections from the SIEM appliance, or unauthorized file modifications, which could indicate successful exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-31T13:38:25Z","date_published":"2026-07-31T13:38:25Z","id":"https://feed.craftedsignal.io/briefs/2026-07-logsign-code-injection/","summary":"Logsign SIEM versions prior to 6.4.108 are vulnerable to a critical code injection flaw (CVE-2026-17561) that enables unauthenticated remote attackers to achieve arbitrary code execution.","title":"Unauthenticated Remote Code Injection in Logsign SIEM","url":"https://feed.craftedsignal.io/briefs/2026-07-logsign-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Innotim Software, Telecommunications and Consulting Trade Ltd. Co.","version":"https://jsonfeed.org/version/1.1"}