CVE-2026-57956: SigNoz < 0.133.0 - Cross-Organization Insecure Direct Object Reference in Alert Rules
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57956?
The severity of CVE-2026-57956 is medium with a score of 6.4.
How do I fix CVE-2026-57956?
To fix CVE-2026-57956, ensure that access controls are correctly implemented to restrict alert rule access by organization ID.
What can attackers do with CVE-2026-57956?
Attackers can read, edit, and delete alert rules of other organizations by exploiting the insecure direct object reference.
Which software is affected by CVE-2026-57956?
CVE-2026-57956 affects SigNoz versions up to and including 0.130.1.
When was CVE-2026-57956 published?
CVE-2026-57956 was published on June 29, 2026.