CVE-2026-92729

Source
https://cve.org/CVERecord?id=CVE-2026-92729
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92729.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92729
Aliases
  • GHSA-v549-7j2x-qjm5
Published
2026-09-16T18:31:19Z
Modified
2026-09-18T03:48:44Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints
Details

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306",
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92729.json"
}
References

Affected packages

Git / github.com/signoz/signoz

Affected ranges

Type
GIT
Repo
https://github.com/signoz/signoz
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.88.0"
        },
        {
            "fixed": "0.141.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.100.0
v0.100.1
v0.101.0
v0.101.0-rc.1
v0.102.0
v0.102.1
v0.103.0
v0.103.1
v0.104.0
v0.104.0-cloud.1
v0.105.0
v0.105.1
v0.106.0
v0.107.0
v0.108.0
v0.108.0-rc.1
v0.109.0
v0.109.1
v0.109.2
v0.109.3
v0.110.0
v0.110.1
v0.111.0
v0.112.0
v0.112.1
v0.113.0
v0.113.0-rc.1
v0.114.0
v0.114.1
v0.115.0
v0.116.0
v0.116.1
v0.117.0
v0.117.1
v0.118.0
v0.119.0
v0.120.0
v0.121.0
v0.121.1
v0.122.0
v0.123.0
v0.124.0
v0.125.0
v0.125.1
v0.126.0
v0.126.1
v0.126.3-rc.1
v0.127.0
v0.127.1
v0.128.0
v0.129.0
v0.130.0
v0.130.1
v0.131.0
v0.131.1
v0.132.0
v0.132.0-rc.1
v0.132.0-rc.2
v0.132.1
v0.132.2
v0.133.0
v0.134.0
v0.134.0-cloud.1
v0.134.0-cloud.2
v0.135.0
v0.135.0-cloud.1
v0.135.0-cloud.2
v0.135.0-cloud.3
v0.135.0-cloud.4
v0.135.0-cloud.5
v0.135.1
v0.136.0
v0.136.1
v0.137.0
v0.137.1
v0.138.0
v0.139.0
v0.140.0
v0.141.0
v0.88.0
v0.88.1
v0.89.0
v0.90.0
v0.90.1
v0.91.0
v0.91.1
v0.92.0
v0.92.0-cloud.1
v0.92.0-rc.1
v0.92.0-rc.5
v0.92.1
v0.92.2
v0.93.0
v0.93.0-cloud.1
v0.93.0-cloud.2
v0.93.0-cloud.3
v0.93.0-rc.1
v0.93.0-rc.2
v0.93.0-rc.3
v0.94.0
v0.94.1
v0.94.1-cloud.1
v0.95.0
v0.95.1
v0.95.1-cloud.1
v0.96.0
v0.96.1
v0.97.0
v0.97.0-rc.1
v0.97.0-rc.2
v0.97.0-rc.3
v0.97.1
v0.98.0
v0.98.0-rc.0
v0.98.0-rc.1
v0.99.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92729.json"