CVE-2026-92729
SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
| CWE | CWE-306 CWE-862 |
| Vendor | signoz |
| Product | signoz |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for signoz signoz
Be the first to know when new high vulnerabilities affecting signoz signoz are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
Low
Affected Versions
SigNoz / signoz
0.88.0 < 0.141.1
References
github.com: https://github.com/SigNoz/signoz/security/advisories/GHSA-v549-7j2x-qjm5 github.com: https://github.com/SigNoz/signoz/pull/12817 github.com: https://github.com/SigNoz/signoz/commit/f78bd492d8732f011bc96837cf9862db2df0783d github.com: https://github.com/SigNoz/signoz/releases/tag/v0.141.1 github.com: https://github.com/SigNoz/signoz/blob/v0.141.0/pkg/query-service/app/http_handler.go#L4073-L4086 github.com: https://github.com/SigNoz/signoz vulncheck.com: https://www.vulncheck.com/advisories/signoz-0.88.0-through-0.141.0-missing-authentication-on-trace-funnel-analytics-endpoints
Credits
4NK1T lighthousekeeper1212 0xVijay axel-corsiez morimori-dev PLpaPLpa newugly thaidn (Calif.io, in collaboration with Anthropic) hackchang Wenhao Wu (d3do-23), Southeast University