PT-2026-97690 · Signoz · Signoz

·

CVE-2026-97055

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SigNoz versions 0.8.0 through 0.142.0
Description Deployments that do not configure a signing secret for the JWT tokenizer use an empty string as the default HMAC key for signing and verifying session tokens. This occurs because the Config.Validate() function does not reject empty values. An unauthenticated attacker can forge valid session tokens for any user, including administrators, by signing the id, orgId, and email claims with an empty key. The organization ID and email registration status can be retrieved without authentication via the '/api/v2/sessions/context' endpoint. Additionally, a forged refresh token can be exchanged for a new token pair through the '/api/v2/sessions/rotate' endpoint and cannot be revoked, remaining valid for its full lifetime.
Recommendations Update to version 0.143.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97055
GHSA-C26W-G4J8-39M2

Affected Products

Signoz