


Perceptive Security
SOC/SIEM Consultancy

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to interc…
Published:
2 August 2026 at 22:00:00
Alert date:
3 August 2026 at 21:04:01
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies, Identity & Access
Emlog Pro through version 2.6.23 contains a critical TLS certificate validation vulnerability in include/service/ai.php. The CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST options are unconditionally disabled across four functions: sendStream(), sendImageRequest(), send(), and fetchSearchHtml(). This allows network-adjacent attackers to perform man-in-the-middle attacks by presenting arbitrary TLS certificates to intercept outbound HTTPS requests to configured LLM providers. Attackers can extract Authorization Bearer API keys from AI requests and inject crafted AI responses into the tool-call execution pipeline. The impact is significant as injected responses may be acted upon by dangerous tool handlers including query_database and update_config. There is no option available to re-enable TLS verification, making this a systemic flaw rather than a misconfiguration.
Technical details
Mitigation steps:
Affected products:
Emlog Pro 2.6.23
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67598
https://github.com/emlog/emlog/security/advisories/GHSA-hf85-99vj-m4c5
https://www.vulncheck.com/advisories/emlog-pro-tls-certificate-validation-disabled-in-ai-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
