CVE-2026-57956

SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-29 18:16

Updated : 2026-07-20 16:17


NVD link : CVE-2026-57956

Mitre link : CVE-2026-57956

CVE.ORG link : CVE-2026-57956


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key