{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/innotim/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:innotim:logsign_siem:6.4.101:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-90924"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Logsign SIEM (6.4.101 to \u003c6.4.117)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","authentication","siem"],"_cs_type":"advisory","_cs_vendors":["Innotim"],"content_html":"\u003cp\u003eLogsign SIEM, developed by Innotim Software, Telecommunications and Consultancy Trade Ltd. Co., contains a critical vulnerability identified as CVE-2026-90924. This vulnerability arises from the use of default credentials within the application, allowing an attacker to bypass authentication mechanisms by leveraging common or default usernames and passwords. The scope of this issue affects product versions from 6.4.101 up to, but not including, 6.4.117. Given that SIEM platforms often ingest sensitive logs and hold administrative privileges across an organization's network, unauthorized access via this flaw could lead to full platform compromise, data exfiltration, or the tampering of security audit trails. Organizations running affected versions are at high risk of unauthenticated access by remote adversaries who identify the SIEM instance.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability grants an attacker unauthorized administrative access to the Logsign SIEM interface. In a security operations context, this allows an adversary to view sensitive security telemetry, disable alerting, modify correlation rules, or gain pivot points into the broader internal infrastructure. As Logsign SIEM is a centralized repository for enterprise security data, compromise results in a loss of visibility and integrity for the entire SOC ecosystem.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of all Logsign SIEM installations to version 6.4.117 or later to address CVE-2026-90924. If an immediate upgrade is not feasible, restrict network access to the SIEM management interface to authorized administrative segments only. Audit current user accounts for unauthorized modifications or unexpected login patterns from external IP addresses. Monitor web server logs for high-frequency login attempts directed at the SIEM administrative interface.\u003c/p\u003e\n","date_modified":"2026-09-28T16:20:21Z","date_published":"2026-09-28T16:20:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-logsign-default-creds/","summary":"Logsign SIEM versions 6.4.101 through 6.4.116 contain a critical default credential vulnerability that permits unauthorized access via known usernames and passwords.","title":"Default Credential Vulnerability in Logsign SIEM","url":"https://feed.craftedsignal.io/briefs/2026-09-logsign-default-creds/"}],"language":"en","title":"CraftedSignal Threat Feed - Innotim","version":"https://jsonfeed.org/version/1.1"}