PT-2026-53674 · Signoz · Signoz
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
SigNoz versions prior to 0.130.2
Description
Broken access control allows authenticated users to access alert rules of other organizations. This occurs because the alert rule store predicates fail to filter by organization ID, resulting in a missing tenant isolation check. By supplying a target rule UUID, an attacker can bypass multi-tenant access controls to read, edit, and delete alert rules belonging to other organizations.
Recommendations
Update SigNoz to version 0.130.2 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Signoz