Broken Access Control in SigNoz Allows Unauthorized Access to Alert Rules
CVE-2026-57956

6.1MEDIUM

Key Information:

Vendor

Signoz

Status
Vendor
CVE Published:
29 June 2026

What is CVE-2026-57956?

The SigNoz application prior to version 0.130.1 is susceptible to a broken access control vulnerability that enables authenticated users to interact with alert rules that belong to other organizations. This flaw occurs due to insufficient filtering by organization ID in the alert rule storage predicates, allowing attackers to read, edit, and delete alert rules indiscriminately across different organizations. Without proper tenant isolation, the multi-tenant access controls are effectively bypassed, posing a significant risk to data integrity and user privacy.

Affected Version(s)

signoz 0 <= 0.130.1

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.