Improper Certificate Validation in Emlog Pro - CVE-2026-67598
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper certificate validation in the AI service HTTP client when sending outbound HTTPS requests to configured AI providers. A remote attacker can intercept the connection with an attacker-controlled certificate to disclose sensitive information.
Only instances with the AI assistant configured and an API key set are vulnerable. The issue also affects chat completions, image generation, and the @em-help Bing/FAQ search feature.