CVE-2026-90924
Deferred Deferred - Pending Action

Default Credentials in Logsign SIEM

Vulnerability report for CVE-2026-90924, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
innotim_software logsign_siem From 6.4.101 (inc) to 6.4.117 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1392 The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the use of default credentials in Logsign SIEM software by Innotim Software. It allows attackers to exploit common or default usernames and passwords, potentially gaining unauthorized access to the system.

Detection Guidance

Detect this vulnerability by scanning for default credentials on Logsign SIEM systems. Check for accounts using default usernames and passwords, particularly in versions 6.4.101 to 6.4.117. Use network scanners like Nmap with default credential checks or manual inspection of login pages.

Impact Analysis

An attacker could exploit this to gain full control over the Logsign SIEM system, leading to data breaches, unauthorized access to sensitive information, or disruption of services. The high CVSS score indicates severe potential impact.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations due to unauthorized data access or breaches. It may result in legal penalties, loss of trust, and reputational damage.

Mitigation Strategies

Immediately update Logsign SIEM to version 6.4.117 or later to address the default credentials issue. Disable or remove any default accounts and enforce strong password policies. Monitor for unauthorized access attempts and audit user accounts regularly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90924. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart