A critical unauthenticated code injection flaw (CVSS 9.8) affects all Logsign SIEM versions before 6.4.108, allowing remote attackers to execute arbitrary code on a platform that sits at the center of an organization's security telemetry.
What Is It
CVE-2026-17561 is an Improper Control of Generation of Code ('Code Injection') vulnerability, CWE-94, in Logsign SIEM, developed by Innotim Software, Telecommunications and Consulting Trade Ltd. Co. The flaw allows code injection against affected deployments.
It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That breaks down to network-reachable attack surface, low attack complexity, no privileges required, and no user interaction; with high impact to confidentiality, integrity, and availability. Exploitability scores 3.9 out of a possible 3.9; impact scores 5.9.
The CVE was published 2026-07-31 and reported by USOM ([email protected]), Turkey's national CSIRT. Its NVD status is currently "Received," meaning the record has not yet completed full NVD analysis.
Why It Matters
The precondition stack here is the worst case: no credentials, no clicks, remote access, and full compromise of all three impact dimensions. A SIEM is a high-value target; it aggregates logs from across the estate and often holds broad read access and integration credentials. Code execution on that platform is both a direct compromise and a potential foothold for tampering with the very records that would reveal an intrusion.
No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation and no federal remediation deadline on record at this time.
What's Vulnerable
- Vendor: Innotim Software, Telecommunications and Consulting Trade Ltd. Co.
- Product: Logsign SIEM
- Affected versions: all versions before 6.4.108 (default status for other versions: unaffected)
No CPE match strings are listed in the current NVD record.
Patch Status
The version data indicates the issue is resolved in Logsign SIEM 6.4.108; versions at or above that are marked unaffected. Operators running anything below 6.4.108 should upgrade. No workaround or mitigation guidance is present in the supplied source material.
Sources
- NVD, CVE-2026-17561: https://nvd.nist.gov/vuln/detail/CVE-2026-17561
- USOM (Turkish National Cyber Incident Response Center) advisory TR-26-0717: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0717