CVE-2026-16900: Authentication bypass in local collector registration in Eventlog analyzer and Log360
| Vulnerability details |
| Severity |
High |
| CVE ID |
CVE-2026-16900 |
| Affected software versions |
Builds 13070 and earlier |
| Fixed version |
Build 13071 |
| Fixed on |
August 25, 2026 |
Details
CVE-2026-16900 is an Authentication bypass in local collector registrations in EventLog Analyzer and Log360, where an unauthenticated actor can register a local collector by sending a crafted registration request.
Impact
An unauthenticated actor could exploit this vulnerability to impersonate a local collector, gaining access to sensitive configuration data and adding unauthorized syslog sources to inject fabricated log data
Fix
The vulnerability has been addressed by implementing additional validation during local collector registration to prevent local collector spoofing.
Steps to update
Update your Log360 or EventLog Analyzer installation to build 13071 or later using the following links
Acknowledgements
This issue was identified by Sus through the Zoho Bug Bounty Program.
Please contact our product support or our security team if you need further assistance.