TLS Certificate Validation Flaw in Emlog Pro by Emlog
CVE-2026-67598
Key Information:
Badges
What is CVE-2026-67598?
Emlog Pro, as of version 2.6.23, is susceptible to a TLS certificate validation vulnerability that allows attackers in the same network vicinity to intercept HTTPS requests. This exploitation arises from the unconditional disabling of the CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST options in various functions, including sendStream() and fetchSearchHtml(). As a result, attackers can leverage this vulnerability to perform man-in-the-middle attacks, capturing sensitive Authorization Bearer API keys and injecting malicious responses into AI requests processed by the application. This poses a significant risk to the integrity of data and interactions denoted by the application.
Affected Version(s)
emlog 0 <= 2.6.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
