PT-2026-97690 · Signoz · Signoz
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SigNoz versions 0.8.0 through 0.142.0
Description
Deployments that do not configure a signing secret for the JWT tokenizer use an empty string as the default HMAC key for signing and verifying session tokens. This occurs because the
Config.Validate() function does not reject empty values. An unauthenticated attacker can forge valid session tokens for any user, including administrators, by signing the id, orgId, and email claims with an empty key. The organization ID and email registration status can be retrieved without authentication via the '/api/v2/sessions/context' endpoint. Additionally, a forged refresh token can be exchanged for a new token pair through the '/api/v2/sessions/rotate' endpoint and cannot be revoked, remaining valid for its full lifetime.Recommendations
Update to version 0.143.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Signoz