PT-2026-97691 · Signoz · Signoz

CVE-2026-97056

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SigNoz versions 0.98.0 through 0.142.0
Description When configured to use the opaque session tokenizer, the system fails to revoke existing login sessions during password resets or user deletions. This occurs because the DeleteTokensByUserID function is not called during these processes, leaving cached tokens and identities active. An attacker possessing a session token can maintain full account access, including administrator privileges, even after a password reset (until the token expires, typically 30 days) or after the user is deleted (until the token rotates, typically 30 minutes). This issue affects the following endpoints:
  • POST '/api/v2/factor password/reset' via the UpdatePasswordByResetPasswordToken function
  • DELETE '/api/v2/users/{id}' via the DeleteUser function, where id is the user identifier
Recommendations Update to version 0.143.0.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97056
GHSA-XRGP-3FQ4-XG83

Affected Products

Signoz