top of page
perceptive_background_267k.jpg

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to interc…

Published:

2 August 2026 at 22:00:00

Alert date:

3 August 2026 at 21:04:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Emerging Technologies, Identity & Access

Emlog Pro through version 2.6.23 contains a critical TLS certificate validation vulnerability in include/service/ai.php. The CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST options are unconditionally disabled across four functions: sendStream(), sendImageRequest(), send(), and fetchSearchHtml(). This allows network-adjacent attackers to perform man-in-the-middle attacks by presenting arbitrary TLS certificates to intercept outbound HTTPS requests to configured LLM providers. Attackers can extract Authorization Bearer API keys from AI requests and inject crafted AI responses into the tool-call execution pipeline. The impact is significant as injected responses may be acted upon by dangerous tool handlers including query_database and update_config. There is no option available to re-enable TLS verification, making this a systemic flaw rather than a misconfiguration.

Technical details

Mitigation steps:

Affected products:

Emlog Pro 2.6.23

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page