PT-2026-60776 · Signoz · Signoz

·

CVE-2026-63094

·

Published

2026-07-17

·

Updated

2026-07-27

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SigNoz versions prior to 0.133.1
Description An open redirect flaw exists in the SSO authentication flow for instances configured with Google OAuth, SAML, or OIDC. Unauthenticated attackers can exploit this by calling the sessions context endpoint with a ref parameter pointing to a host under their control. By delivering a crafted login URL to a victim, the attacker can steal the victim's access and refresh tokens upon completion of the SSO authentication process.
Recommendations Update SigNoz to version 0.133.1 or later. As a temporary mitigation, restrict access to the sessions context endpoint or avoid using the ref parameter in SSO flows until the update is applied.

Exploit

Fix

Open Redirect

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63094

Affected Products

Signoz