CVE-2025-62189: Secuavail Logstare Collector

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request.

Affected products

  • Secuavail Logstare Collector: before 2.4.2 (fixed in 2.4.2)

Published 2025-11-21. Last modified 2026-06-17.