PT-2026-97691 · Signoz · Signoz
CVE-2026-97056
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SigNoz versions 0.98.0 through 0.142.0
Description
When configured to use the opaque session tokenizer, the system fails to revoke existing login sessions during password resets or user deletions. This occurs because the
DeleteTokensByUserID function is not called during these processes, leaving cached tokens and identities active. An attacker possessing a session token can maintain full account access, including administrator privileges, even after a password reset (until the token expires, typically 30 days) or after the user is deleted (until the token rotates, typically 30 minutes). This issue affects the following endpoints:- POST '/api/v2/factor password/reset' via the
UpdatePasswordByResetPasswordTokenfunction - DELETE '/api/v2/users/{id}' via the
DeleteUserfunction, whereidis the user identifier
Recommendations
Update to version 0.143.0.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Signoz