{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/signoz-0.87.0--v--0.142.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:signoz:signoz:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-92729"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SigNoz (0.88.0 - 0.141.0)","SigNoz (0.88.0 \u003c= v \u003c 0.142.1)","SigNoz (0.87.0 \u003c= v \u003c 0.142.0)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","api-security","observability","sql-injection","vulnerability","web-application","webserver","injection"],"_cs_type":"advisory","_cs_vendors":["SigNoz"],"content_html":"\u003cp\u003eSigNoz versions 0.88.0 through 0.141.0 contain a critical authorization bypass vulnerability within the application's trace-funnel analytics endpoints. The vulnerability stems from a failure to implement necessary authorization wrappers on specific HTTP handlers responsible for processing trace-funnel requests. This oversight allows unauthenticated remote attackers to submit arbitrary funnel definitions to the API. By interacting with these unprotected endpoints, attackers can exfiltrate sensitive observability data, including trace identifiers, request durations, span counts, internal service topology, and error activity metrics. Because these endpoints do not validate user credentials, this vulnerability poses a significant risk for unauthorized information disclosure of internal system architecture and operational telemetry. Defending against this threat requires identifying and restricting access to the affected funnel analytics endpoints or upgrading to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in unauthorized exposure of sensitive operational data. Successful exploitation allows an attacker to map service dependencies, identify high-frequency error patterns, and monitor traffic volumes, which can be used to inform further reconnaissance against the internal network. No specific victim counts are currently available, but any organization running versions 0.88.0 through 0.141.0 is at risk of remote telemetry exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous POST requests directed at trace-funnel analytic endpoints originating from unauthorized IP ranges.\u003c/li\u003e\n\u003cli\u003eAudit ingress traffic to identify unauthenticated requests to SigNoz API paths associated with trace analytics.\u003c/li\u003e\n\u003cli\u003eImplement strict network-level access control (e.g., WAF rules or VPN-only access) for the SigNoz API until an upgrade to a patched version is completed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T00:03:44Z","date_published":"2026-09-16T19:52:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-signoz-auth-bypass/","summary":"SigNoz versions 0.88.0 through 0.141.0 contain an authorization bypass vulnerability allowing unauthenticated remote attackers to query sensitive trace analytics via the trace-funnel endpoint.","title":"Authorization Bypass in SigNoz Trace-Funnel Analytics","url":"https://feed.craftedsignal.io/briefs/2026-09-signoz-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - SigNoz (0.87.0 \u003c= v \u003c 0.142.0)","version":"https://jsonfeed.org/version/1.1"}