CVE-2026-14564
Received
Received - Intake
Insufficiently Protected Credentials in Logsign SIEM
Vulnerability report for CVE-2026-14564, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-17
Last updated on: 2026-08-17
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data.
This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| logsign | siem | From 6.4.97 (inc) to 6.4.114 (exc) |
| innotim_software_telecommunications_and_consulting_trade_ltd_co. | logsign_siem | From 6.4.97 (inc) to 6.4.114 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |