CVE-2026-93426

Source
https://cve.org/CVERecord?id=CVE-2026-93426
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93426.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93426
Aliases
  • GHSA-q3h7-gpc9-2rxc
Published
2026-09-17T21:19:12Z
Modified
2026-09-20T11:47:29Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N CVSS Calculator
Summary
SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names
Details

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-89"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93426.json"
}
References

Affected packages

Git / github.com/signoz/signoz

Affected ranges

Type
GIT
Repo
https://github.com/signoz/signoz
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.87.0"
        },
        {
            "fixed":  "0.142.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93426.json"