SQL Injection Vulnerability in SigNoz Trace Funnel Analytics Endpoints
CVE-2026-93292
8.4HIGH
What is CVE-2026-93292?
Versions of SigNoz from 0.88.0 up to but not including 0.142.1 are susceptible to a SQL injection flaw present in trace funnel analytics endpoints. This vulnerability arises from the unsafe interpolation of the 'service_name' and 'span_name' fields into ClickHouse string literals without proper escaping. Authenticated attackers can exploit this issue by injecting malicious SQL through the funnel step definitions, allowing them to execute arbitrary queries and retrieve sensitive data from HTTP responses.
Affected Version(s)
signoz 0.88.0 < 0.142.1
signoz 0.142.1
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
4NK1T
axel-corsiez
morimori-dev
newugly
thaidn (Calif.io, in collaboration with Anthropic)
hackchang
Scott Moore - VulnCheck
