PT-2026-93909 · Signoz · Signoz
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SigNoz versions 0.88.0 through 0.141.0
Description
The HTTP handler fails to apply authorization wrappers to trace-funnel analytics endpoints. This allows unauthenticated attackers to submit arbitrary funnel definitions to retrieve trace analytics, including identifiers, durations, span counts, service topology, and error activity, without providing credentials.
Recommendations
Update SigNoz to a version later than 0.141.0.
Exploit
Fix
Missing Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Signoz