SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
References
Configurations
No configuration.
History
16 Sep 2026, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 19:18
Updated : 2026-09-16 20:21
NVD link : CVE-2026-92729
Mitre link : CVE-2026-92729
CVE.ORG link : CVE-2026-92729
JSON object : View
Products Affected
No product.
