CVE-2026-92729 PUBLISHED

SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor SigNoz
Product signoz
Versions Default: unaffected
  • affected from 0.88.0 to 0.141.1 (excl.)

Credits

  • 4NK1T finder
  • lighthousekeeper1212 finder
  • 0xVijay finder
  • axel-corsiez finder
  • morimori-dev finder
  • PLpaPLpa finder
  • newugly finder
  • thaidn (Calif.io, in collaboration with Anthropic) finder
  • hackchang finder
  • Wenhao Wu (d3do-23), Southeast University finder

References

Problem Types

  • Missing Authentication for Critical Function CWE
  • Missing Authorization CWE