CVE-2026-92729: SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SigNozto a version that resolves this vulnerability.Fixed in 0.141.0
Event History
Frequently Asked Questions
Which deployments are exposed?
SigNoz versions 0.88.0 through 0.141.0 are affected if their trace-funnel analytics endpoints are reachable by an attacker. The issue is remotely exploitable without authentication.
What can an unauthenticated attacker obtain?
An attacker can submit arbitrary funnel definitions and retrieve trace analytics. Exposed data includes identifiers, durations, span counts, service topology, and error activity.
Does exploitation require credentials or user interaction?
No. The affected HTTP handler lacks authorization wrappers for these endpoints, so exploitation requires neither credentials nor user interaction.