Signoz · Signoz · CVE-2026-97055
**Name of the Vulnerable Software and Affected Versions**
SigNoz versions 0.8.0 through 0.142.0
**Description**
Deployments that do not configure a signing secret for the JWT tokenizer use an empty string as the default HMAC key for signing and verifying session tokens. This occurs because the `Config.Validate()` function does not reject empty values. An unauthenticated attacker can forge valid session tokens for any user, including administrators, by signing the `id`, `orgId`, and `email` claims with an empty key. The organization ID and email registration status can be retrieved without authentication via the '/api/v2/sessions/context' endpoint. Additionally, a forged refresh token can be exchanged for a new token pair through the '/api/v2/sessions/rotate' endpoint and cannot be revoked, remaining valid for its full lifetime.
**Recommendations**
Update to version 0.143.0 or later.