CRITICAL 9.1 NVD
CVE-2026-67598
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to interc
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and fetchSearchHtml() with no option to re-enable verification. Attackers can perform man-in-the-middle interception to extract Authorization Bearer API keys from every AI request and inject crafted AI responses that may be acted upon by the tool-call execution pipeline, including the query_database and update_config tool handlers.
References
- https://github.com/emlog/emlog/security/advisories/GHSA-hf85-99vj-m4c5
- https://www.vulncheck.com/advisories/emlog-pro-tls-certificate-validation-disabled-in-ai-p
- https://github.com/emlog/emlog/security/advisories/GHSA-hf85-99vj-m4c5
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-08-03 via NVD.
Risk Timeline
CVE Disclosed2026-08-03 · 0 days ago
Remediation Resources
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.