Description
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

Authenticated users with a Viewer role or higher can exploit a flaw in the v5 query_range API of SigNoz by embedding backticks and quotes in telemetry field-key names. The application fails to properly escape these values, allowing attackers to break out of identifiers and string literals. The resulting injection enables arbitrary ClickHouse SQL execution, which can read system tables and exfiltrate sensitive data. This vulnerability is a classic example of SQL injection, identified by CWE-89.

Affected Systems

All SigNoz installations running versions 0.87.0 through 0.141.x are affected. The flaw exists in the codebase prior to the release of version 0.142.0, which introduced proper escaping for field-key names in the query builder.

Risk and Exploitability

With a CVSS score of 8.4, this vulnerability is considered high severity. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Nevertheless, authenticated attackers who can assign field-key names can execute malicious queries. The attack vector requires user credentials with at least Viewer privileges and can be carried out by submitting specially crafted field-key names to the query_range endpoint. The impact includes unauthorized data access and potential data exfiltration from the ClickHouse backend.

Generated by OpenCVE AI on September 19, 2026 at 08:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SigNoz to version 0.142.0 or later to apply the escaping fix for field-key names
  • Restrict access to the v5 query_range API by limiting the Viewer role to trusted users or removing the role where possible
  • Implement input validation that rejects backticks, quotes, or other special characters in field-key names before the request is processed
  • Enable logging of query_range requests and monitor for suspicious field-key name patterns to detect attempted injection attempts

Generated by OpenCVE AI on September 19, 2026 at 08:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Signoz
Signoz signoz
Vendors & Products Signoz
Signoz signoz

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.
Title SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T20:05:37.112Z

Reserved: 2026-09-17T21:00:02.150Z

Link: CVE-2026-93426

cve-icon Vulnrichment

Updated: 2026-09-18T20:05:33.413Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T22:17:04.597

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:15:14Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')