


Perceptive Security
SOC/SIEM Consultancy

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to interc…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 21:04:01
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies, Identity & Access
Emlog Pro through version 2.6.23 contains a critical TLS certificate validation vulnerability in include/service/ai.php. The CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST options are unconditionally disabled across four functions: sendStream(), sendImageRequest(), send(), and fetchSearchHtml(). This allows network-adjacent attackers to perform man-in-the-middle attacks by presenting arbitrary TLS certificates to intercept outbound HTTPS requests to configured LLM providers. Attackers can extract Authorization Bearer API keys from AI requests and inject crafted AI responses into the tool-call execution pipeline. The impact is significant as injected responses may be acted upon by dangerous tool handlers including query_database and update_config. There is no option available to re-enable TLS verification, making this a systemic flaw rather than a misconfiguration.
Technical details
Mitigation steps:
Affected products:
Emlog Pro 2.6.23
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67598
https://github.com/emlog/emlog/security/advisories/GHSA-hf85-99vj-m4c5
https://www.vulncheck.com/advisories/emlog-pro-tls-certificate-validation-disabled-in-ai-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
