CVE-2026-92905: Denial of service in log collector in EventLog Analyzer and Log360

Vulnerability details
Severity Medium
CVE ID CVE-2026-92905
Affected software versions Builds 13070 and earlier
Fixed version Build 13071
Fixed on August 25 2026

Details

CVE-2026-92905 is a denial-of-service vulnerability in the log collector component of EventLog Analyzer and Log360, where malformed syslog datagrams sent to the syslog listener port were not handled correctly, causing the collector service to stop unexpectedly.

Impact

An unauthenticated actor with network access to the syslog listener could crash the log collector service, interrupting syslog collection until the update is applied.

Fix

The vulnerability has been addressed by improving input validation in the log collector so that malformed datagrams are discarded safely and the service continues to run.

Steps to update

Update your Log360 or EventLog Analyzer installation to build 13071 or later using the following links:

Acknowledgements

This issue was identified by Seth through the Zoho Bug Bounty Program.

Please contact our product support or our security team if you need further assistance.