PT-2026-67487 · Emlog Pro · Emlog Pro

·

CVE-2026-67598

·

Published

2026-08-03

·

Updated

2026-08-04

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Emlog Pro versions prior to 2.6.24
Description In the file include/service/ai.php, TLS certificate validation is disabled, allowing network-adjacent attackers to intercept outbound HTTPS requests to configured Large Language Model (LLM) providers by presenting arbitrary TLS certificates. This occurs because CURLOPT SSL VERIFYPEER and CURLOPT SSL VERIFYHOST are unconditionally disabled within the sendStream(), sendImageRequest(), send(), and fetchSearchHtml() functions. Attackers can execute a man-in-the-middle attack to extract Authorization Bearer API keys from AI requests and inject malicious AI responses. These responses may be processed by the tool-call execution pipeline, specifically affecting the query database and update config tool handlers.
Recommendations Update Emlog Pro to version 2.6.24 or later. As a temporary mitigation, restrict network access to the include/service/ai.php component to prevent unauthorized interception of outbound requests.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67598
GHSA-HF85-99VJ-M4C5

Affected Products

Emlog Pro