Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-90924: Logsign SIEM can be accessed with default admin credentials

CVE-2026-90924 · published 4 days ago
Summary

The Logsign SIEM version 6.4.101 through 6.4.116 accepts the factory‑set username and password, so anyone who knows these defaults can log in. This could let an attacker view or change security logs and settings. Update to the latest version or change the default admin password immediately.

What to do
  • Update innotim software, telecommunications and consultancy trade ltd. co. logsign siem to version 6.4.117 or later.
Affected software
VendorProductAffected versions
innotim software, telecommunications and consultancy trade ltd. co. logsign siem < 6.4.117
Original advisory text
Default Admin Credentials in Innotim Software's Logsign SIEM
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords.

This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1392Use of Default Credentials
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-90924 · MITRE
Track software like this
Free during beta