Signoz · Signoz · CVE-2026-92729
**Name of the Vulnerable Software and Affected Versions**
SigNoz versions 0.88.0 through 0.141.0
**Description**
The HTTP handler fails to apply authorization wrappers to trace-funnel analytics endpoints. This allows unauthenticated attackers to submit arbitrary funnel definitions to retrieve trace analytics, including identifiers, durations, span counts, service topology, and error activity, without providing credentials.
**Recommendations**
Update SigNoz to a version later than 0.141.0.