External risk intelligence

Logsign SIEM Default Credentials Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90924

Logsign SIEM is a security information and event management platform. These systems often operate as centralized management appliances or gateways within a network, and their management interfaces are frequently exposed or reachable across network segments to aggregate logs, making them a common target for network-based access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Logsign SIEM product, impacting its ability to secure sensitive information and operations. The issue stems from the use of default credentials, which could allow unauthorized access to the system. Given that Logsign SIEM often functions as a central security management point, its compromise could have broad implications for an organization's security posture. The primary concern at this time is to determine if this product is in use and, if so, to understand the extent of its exposure.

  • Default passwords create a security risk.
  • Central security systems require diligent oversight.
  • Confirm use and exposure to assess relevance.

Attack Path

How an attacker could exploit the issue

An attacker could target the Logsign SIEM system by attempting to log in using common or default usernames and passwords. If successful, this unauthorized access to the system's management interface could lead to severe compromise of the security information and event management capabilities.

  • Unauthenticated network access.
  • Default or common credentials.
  • Complete system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Logsign SIEM could allow an attacker to access the system using default or commonly known credentials. When supported by the advisory, this could lead to unauthorized access and manipulation of the SIEM's security data and functions.

  • Sensitive security data may be exposed.
  • Attackers can attempt default credentials.
  • Unauthorized access to security data.

Operational Fix

Recommended remediation, mitigation, and detection steps

Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM, a security information and event management platform, is affected by a critical vulnerability due to the use of default credentials. This could allow unauthorized access across the network. The first practical step is to identify all Logsign SIEM instances, confirm their network reachability and business criticality, and then engage the accountable owner to plan remediation based on risk.

  • Security or platform teams should own the issue.
  • Verify network exposure and default credential usage.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Logsign SIEM?

Logsign SIEM is a security information and event management platform developed by Innotim Software. Organizations use it to aggregate logs and manage security data from across their network, acting as a central hub for monitoring and analysis.

How does CWE-1392 affect CVE-2026-90924?

This vulnerability is classified as CWE-1392, which refers to the use of default credentials. In the context of CVE-2026-90924, the software is shipped with pre-set usernames and passwords that remain active, creating a significant security gap if these defaults are not changed.

What triggers this Logsign SIEM vulnerability?

An attacker triggers this flaw by attempting to authenticate using the software's known default usernames and passwords. Access is not triggered by standard usage or legitimate traffic; it requires a deliberate attempt to log in using these specific, unchanged credentials.

Is my Logsign SIEM instance at risk?

According to Halo Surface Signal, Logsign SIEM systems often operate as central gateways or management appliances. If your instance is reachable across network segments or exposed to the internet to collect logs, it is more likely to be targeted for this type of network-based unauthorized access.

How do I respond to CVE-2026-90924?

Your first step is to locate all instances of Logsign SIEM in your environment and verify if they are running the affected versions. Coordinate with the system owners to confirm if default credentials are still in place and prioritize updating or securing those configurations to prevent unauthorized entry.

References