CVE-2026-93292: SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders

Published Sep 17, 2026
·
Updated

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate servicename and spanname fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.

Affected Software

1 affected component
SigNoz SigNoz>=0.88.0<0.142.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SigNoz to a version that resolves this vulnerability.

    Fixed in 0.142.1Patch SQL Injection in Trace Funnel Analytics Query Builders

Event History

Sep 17, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated attacker with access to the trace-funnel analytics endpoints can exploit it. No user interaction is required, and the attack can be performed remotely.

2

What access does exploitation provide?

An attacker can inject SQL through funnel step service_name or span_name values, execute arbitrary ClickHouse queries, and read query results returned in HTTP responses. The reported impact includes high confidentiality impact and low integrity impact.

3

Which deployments are affected?

SigNoz versions from 0.88.0 up to, but not including, 0.142.1 are affected. Deployments running 0.142.1 or later are not identified as affected by the provided advisory data.

4

What should teams do if they cannot immediately upgrade?

The provided data does not identify a configuration workaround. Until upgrading, restrict access to authenticated users who need trace-funnel analytics access and review use of funnel step definitions containing unexpected service_name or span_name values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203