CVE-2026-90926: Code Injection in Innotim Software's Logsign SIEM
Published Sep 28, 2026
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection.
This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
Affected Software
1 affected component
Innotim Software Logsign SIEM>=6.4.101<6.4.117
Event History
Sep 28, 2026
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Logsign SIEM versions from 6.4.101 through versions before 6.4.117 are affected. The provided information does not identify any affected versions outside that range.
2
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates network-reachable exploitation with low attack complexity, low privileges required, and no user interaction. Successful exploitation can have high impact on confidentiality, integrity, and availability.