Description
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

SigNoz versions 0.88.0 through 0.141.0 do not apply authorization wrappers to the trace‑funnel analytics endpoints in the HTTP handler. As a result, an unauthenticated attacker can submit arbitrary funnel definitions and receive detailed trace analytics that include identifiers, durations, span counts, service topology, and error activity without any credentials.

Affected Systems

All SigNoz deployments running any version from 0.88.0 up to and including 0.141.0 are affected. The vulnerable functionality resides in the HTTP trace‑funnel analytics endpoints exposed by the SigNoz query service.

Risk and Exploitability

The CV score of 8.8 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request to the trace‑funnel analytics endpoint, requiring no authentication. Successful exploitation grants access to detailed trace analytics data without credentials.

Generated by OpenCVE AI on September 18, 2026 at 06:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SigNoz to version 0.141.1 or later, which incorporates the commit that restores proper authorization on trace‑funnel endpoints.
  • If an immediate upgrade is not feasible, restrict access to the trace‑funnel analytics endpoints at the network level by using firewall rules or a reverse proxy that requires authentication before reaching SigNoz.
  • Monitor HTTP logs for requests to the trace‑funnel analytics endpoints lacking authentication and block or mitigate offending IPs during the transition period.

Generated by OpenCVE AI on September 18, 2026 at 06:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Signoz
Signoz signoz
Vendors & Products Signoz
Signoz signoz

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
Title SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints
Weaknesses CWE-306
CWE-862
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T18:18:36.036Z

Reserved: 2026-09-16T17:40:23.128Z

Link: CVE-2026-92729

cve-icon Vulnrichment

Updated: 2026-09-21T18:16:29.024Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:18:06.833

Modified: 2026-09-21T19:17:16.960

Link: CVE-2026-92729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:45:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-862

    Missing Authorization