Description
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch or Upgrade
AI Analysis

Impact

The vulnerability lies in the trace-funnel analytics queries, where the service_name and span_name values are interpolated directly into ClickHouse string literals without any escaping. Because these values are not validated, an attacker who has authenticated access to the system can supply crafted input that modifies the structure of the SQL statement. This enables the attacker to execute arbitrary queries against the ClickHouse database, potentially exposing sensitive data returned in the HTTP response. The attack relies on the fact that the query builder does not use parameterized queries or input validation, making the software susceptible to classic SQL injection.

Affected Systems

SigNoz Signoz versions 0.88.0 through 0.142.0 (inclusive) are affected. Any deployment that exposes the trace funnel analytics endpoints and allows users to create or modify funnel step definitions within this version range is vulnerable.

Risk and Exploitability

The CVSS score of 8.4 marks this issue as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the near term, but the problem remains significant because it requires authentication and grants the ability to execute arbitrary queries. The vulnerability is not in the CISA KEV catalog, yet the potential for data exfiltration and database corruption warrants prompt remediation.

Generated by OpenCVE AI on September 19, 2026 at 09:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SigNoz to version 0.142.1 or later.
  • Ensure that service_name and span_name fields are validated and properly escaped or handled via parameterized queries before inclusion in ClickHouse queries.
  • Limit the ability to create or modify funnel step definitions to trusted, highly privileged users only.

Generated by OpenCVE AI on September 19, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Signoz
Signoz signoz
Vendors & Products Signoz
Signoz signoz

Thu, 17 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
Title SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:53:34.895Z

Reserved: 2026-09-17T16:17:11.416Z

Link: CVE-2026-93292

cve-icon Vulnrichment

Updated: 2026-09-21T20:53:30.443Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T17:18:16.903

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:45:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')