SYS::ONLINE
Wasteland.
Briefs1634
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-17561 2026-07-31

CVE-2026-17561: Critical Code Injection in Logsign SIEM

"A critical unauthenticated code injection flaw (CVSS 9.8) affects all Logsign SIEM versions before 6.4.108, allowing remote attackers to execute arbitrary code on a platform that sits at the center of an organization's…"

A critical unauthenticated code injection flaw (CVSS 9.8) affects all Logsign SIEM versions before 6.4.108, allowing remote attackers to execute arbitrary code on a platform that sits at the center of an organization's security telemetry.

What Is It

CVE-2026-17561 is an Improper Control of Generation of Code ('Code Injection') vulnerability, CWE-94, in Logsign SIEM, developed by Innotim Software, Telecommunications and Consulting Trade Ltd. Co. The flaw allows code injection against affected deployments.

It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That breaks down to network-reachable attack surface, low attack complexity, no privileges required, and no user interaction; with high impact to confidentiality, integrity, and availability. Exploitability scores 3.9 out of a possible 3.9; impact scores 5.9.

The CVE was published 2026-07-31 and reported by USOM ([email protected]), Turkey's national CSIRT. Its NVD status is currently "Received," meaning the record has not yet completed full NVD analysis.

Why It Matters

The precondition stack here is the worst case: no credentials, no clicks, remote access, and full compromise of all three impact dimensions. A SIEM is a high-value target; it aggregates logs from across the estate and often holds broad read access and integration credentials. Code execution on that platform is both a direct compromise and a potential foothold for tampering with the very records that would reveal an intrusion.

No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation and no federal remediation deadline on record at this time.

What's Vulnerable

No CPE match strings are listed in the current NVD record.

Patch Status

The version data indicates the issue is resolved in Logsign SIEM 6.4.108; versions at or above that are marked unaffected. Operators running anything below 6.4.108 should upgrade. No workaround or mitigation guidance is present in the supplied source material.

Sources