Description
A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-06
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Login function in Uptrace's user_handler.go can reveal sensitive information through error messages. The flaw enables an attacker to obtain details such as login failure reasons, potentially revealing usernames or other internal identifiers. This results in an information disclosure vulnerability classified under CWE‑200 and CWE‑209.

Affected Systems

Affected systems are instances of the Uptrace application with versions up to 2.1.0‑beta.8. The issue resides in the pkg/org/user_handler.go file of the Uptrace codebase, and the vulnerability is present in all released binaries up to and including this version. Users running earlier or unsupported releases are considered unaffected.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating medium severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. Attackers can trigger the flaw simply by sending remote requests to the login endpoint; the exploit is publicly disclosed and does not require privileged access. Consequently, the risk of an attacker learning internal information remains significant, especially for systems exposed to the internet.

Generated by OpenCVE AI on October 6, 2026 at 06:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest Uptrace release (above 2.1.0‑beta.8) where the error handling has been corrected.
  • If an update is not immediately possible, restrict access to the login API by rate‑limiting or firewall rules so that only trusted IP addresses can attempt authentication.
  • Review and sanitize error messages in the application to ensure they do not disclose sensitive information; consider configuring Uptrace to suppress detailed error outputs in production environments.
  • Monitor authentication logs for anomalous activity that could indicate exploitation attempts.

Generated by OpenCVE AI on October 6, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title uptrace user_handler.go Login information exposure
First Time appeared Uptrace
Uptrace uptrace
Weaknesses CWE-200
CWE-209
CPEs cpe:2.3:a:uptrace:uptrace:*:*:*:*:*:*:*:*
Vendors & Products Uptrace
Uptrace uptrace
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-06T05:00:16.776Z

Reserved: 2026-10-05T18:27:25.680Z

Link: CVE-2026-105707

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T05:16:38.177

Modified: 2026-10-06T05:16:38.177

Link: CVE-2026-105707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T06:30:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-209

    Generation of Error Message Containing Sensitive Information