CVE-2026-14564 PUBLISHED

Sensitive Data Exposure in Innotim Software's Logsign SIEM

Assigner: TR-CERT
Reserved: 03.07.2026 Published: 17.08.2026 Updated: 17.08.2026

Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data.

This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
CVSS Score: 9

Product Status

Vendor Innotim Software Telecommunications and Consulting Trade Ltd. Co.
Product Logsign SIEM
Versions Default: unaffected
  • affected from 6.4.97 to 6.4.114 (excl.)

Credits

  • Deniz BEKTAŞ finder
  • Banu İKİNCİ remediation developer

References

Problem Types

  • CWE-522 Insufficiently Protected Credentials CWE

Impacts

  • CAPEC-37 Retrieve Embedded Sensitive Data