# Report a Security Vulnerability | Logmanager

[Logmanager](https://logmanager.com/) / [Security center](https://logmanager.com/security/) / [Vulnerability report](https://logmanager.com/security/vulnerability-report/) 

# //Vulnerability Report

 Submit a security vulnerability affecting Logmanager products. All reports are handled by our PSIRT team. Reports are encrypted in transit and stored in a restricted-access system.

🔒

 By submitting this form you agree to our [Coordinated Vulnerability Disclosure Policy](https://logmanager.com/security/coordinated-vulnerability-disclosure-policy/). If you believe the vulnerability is already being actively exploited, please indicate this below — it triggers a regulatory reporting deadline that we are legally required to meet within 24 hours. 

 

 

✅

Report received

Thank you. Your vulnerability report has been submitted to the Logmanager PSIRT team under reference ID **\#**. If you provided contact details, we will get back to you.

 

 

 

  Website  

  01## Affected product

 

 Product \*  Select product… Logmanager Appliance 4.x Logmanager Appliance 3.x Logmanager Forwarder Logmanager Windows Agent Logmanager Logproxy Logmanager Website Other / Unknown 

 

 Version \* Exact version string from System → About



 

 

 Component / Module (optional)  

 Serial number (optional)  

 

  02## Vulnerability details

 

 Vulnerability type \*  Select type… Remote Code Execution (RCE) Local Privilege Escalation (LPE) SQL Injection Cross-Site Scripting (XSS) XML External Entity (XXE) Server-Side Request Forgery (SSRF) Insecure Direct Object Reference (IDOR) Authentication / Authorisation Bypass Information Disclosure Denial of Service Misconfiguration / Insecure Default Supply Chain / Dependency Other 

 

 Short title \* 

 

 Description &amp; technical details \* 

 

 Proof of concept (optional but strongly encouraged) Do not test against production systems or customer environments.

 

 

  03## Severity &amp; exploitation status

 

 Estimated severity (optional)  Critical — CVSS 9.0+

Remote unauthenticated exploit with full system impact

 

   High — CVSS 7.0–8.9

Significant impact requiring authentication or specific conditions

 

   Medium — CVSS 4.0–6.9

Limited impact or requires complex exploitation

 

   Low / Informational — CVSS &lt; 4.0

Minimal impact, defense-in-depth or best practice issue

 

   

 ⚠️ Active exploitation status \*This field has direct legal implications. If you select “actively exploited”, Logmanager is required by the EU Cyber Resilience Act to notify national authorities within 24 hours.

  Yes — I have evidence this is being actively exploited in the wild

I have observed attacks, found it in threat intelligence, or have reliable evidence of in-the-wild exploitation.

 

   Suspected — I have no direct evidence but suspect exploitation is likely

The vulnerability is easy to exploit and/or affects a widely deployed version.

 

   No — I found this during research; no evidence of active exploitation

Discovered during a security audit, penetration test, or independent research.

 

  

 

 

  04## Attachments

 

 Supporting files (optional) Click to upload or drag and drop

PNG, JPG, PDF, TXT, PCAP, ZIP — max 10 MB per file

 

 1. 📎   ✕
  


 

 

  05## Disclosure preferences

 

 Disclosure plans \*  Coordinated — I will work with Logmanager on timing (recommended)

Standard embargo period. We coordinate public release once a fix is available.

 

   Full immediate — I intend to publish regardless of patch status

Please contact us first — we may be able to expedite a fix or workaround.

 

   No public disclosure — I do not intend to publish

The report is strictly provided to Logmanager to fix the issue.

 

   

Submit anonymously

Your contact details will not be collected. Note: We cannot send updates or credit you in advisories.

 

  

 Your name / alias (optional)  

 Email address (optional) 

 

 

 Organisation (optional)  

 GPG / PGP Public Key (optional – for encrypted communications) Prefer encrypted contact? Logmanager PSIRT will use this key to communicate securely with you.

 

 

 

 This form is transmitted over TLS. Data is logged and handled directly by PSIRT security members. 

  Submit report → Submitting…
