HomeSecurityEmlog Assistant: Three critical vulnerabilities in AI function

Emlog Assistant: Three critical vulnerabilities in AI function

Three new vulnerabilities in Emlog open different paths to the database and the administrator account. Emlog Assistant is at the heart of two of the problems, while a third allows unauthorized reinstallation of the platform. Emlog Assistant is where the greatest risk to the database is concentrated.

Emlog Assistant and critical vulnerabilities in websites

The entries were published on August 14, 2026 and concern versions 2.6.26 and earlier, with one of the vulnerabilities even affecting version 2.6.20. The information comes from the corresponding CVE Alert entries, which do not mention a patch available.

See also: Metabase zero-day: Critical SQL injection exposes customer data

Emlog Assistant: Database access

CVE-2026-73847 concerns the execute_tool in admin/ai.php. The lack of CSRF protection allows a remote, unauthenticated attacker to send a forged request via a page they control, provided that an administrator has recently logged in.

The problem is made worse because the query_database passes attacker-controlled values ​​to the query execution process. According to the listing, read queries do not require confirmation, while write queries accept a public confirmation string. The protection is limited to the blog, leaving room for reading other tables and changes to the users table.

In practice, Emlog Assistant is thus transformed from a helper function into a potential entry point to the application's data. The attack does not necessarily require a stolen password, but depends on the recent administrator login and the way the browser handles cookies. This requires control not only of Emlog, but also of the devices used by administrators.

Emlog Assistant and database access risk

Three vulnerabilities, different attack route

CVE-2026-73849 has a CVSS score of 9.8 and is rated critical. The install.php accepts the reinstall without authentication. This could allow a remote attacker to submit database and new administrator credentials, causing settings to be written to config.php and creating an account that they control.

The third entry, CVE-2026-73850, concerns an SQL injection in the queryDatabase of ai.php and affects Emlog 2.6.20 and earlier. Although the page does not provide a rating or a fixed version, the coexistence of the issue with Emlog AI Assistant increases the need for immediate monitoring of installations.

The three entries do not describe the exact same scenario and should not be confused. One concerns forged requests, the second concerns reinstallation, and the third concerns SQL query construction. The common point is that they all touch on functions that are close to administration, platform configuration, or content storage.

Differentiation is important for mitigation. Disabling Emlog AI Assistant alone is not enough for CVE-2026-73849, while blocking install.php does not fix the SQL injection issue. Administrators need to take a version inventory and check each affected endpoint before choosing a workaround.

See also: SourceCodester: Serious SQL injection in dating app

What administrators should check

Until an official update is available, administrators should restrict access to the control panel, isolate install.php from the internet, and consider whether Emlog Assistant is absolutely necessary. Changing administrator and database passwords is prudent when exposure is suspected.

Log checking should look for requests to admin/ai.php and install.php?action=reinstall, new user registrations, changes to config.php , and unusual table access. Also, a backup before each change facilitates recovery, but is not a substitute for digital investigation.

If an unknown account, database login change, or reinstallation request is detected, the installation should be considered suspect until the scan is complete. Restoring a clean copy, replacing credentials, and reviewing database permissions is a safer approach than a single password change.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection measures for Emlog Assistant vulnerabilities

The official Emlog security page asks that vulnerability reports be submitted via email or GitHub Security Advisories and does not yet list a patch for the specific CVE. Organizations hosting Emlog should monitor project announcements and apply the update as soon as it is released.

See also: W3 Total Cache XSS: Critical vulnerability in WordPress websites

Emlog Assistant and new vulnerabilities in Emlog should not be treated as simple entries in a CVE database, especially when they touch management functions and the database. The SecNews technical team recommends limiting exposure, checking for traces of abuse, and immediately upgrading when the project releases an official fix.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS