SQL Injection Vulnerability in SigNoz Trace Funnel Analytics Endpoints
CVE-2026-93292

8.4HIGH

Key Information:

Vendor

Signoz

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-93292?

Versions of SigNoz from 0.88.0 up to but not including 0.142.1 are susceptible to a SQL injection flaw present in trace funnel analytics endpoints. This vulnerability arises from the unsafe interpolation of the 'service_name' and 'span_name' fields into ClickHouse string literals without proper escaping. Authenticated attackers can exploit this issue by injecting malicious SQL through the funnel step definitions, allowing them to execute arbitrary queries and retrieve sensitive data from HTTP responses.

Affected Version(s)

signoz 0.88.0 < 0.142.1

signoz 0.142.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

4NK1T
axel-corsiez
morimori-dev
newugly
thaidn (Calif.io, in collaboration with Anthropic)
hackchang
Scott Moore - VulnCheck
.