SQL Injection Vulnerability in SigNoz by SigNoz
CVE-2026-93426
8.4HIGH
What is CVE-2026-93426?
A security flaw in SigNoz versions prior to 0.142.0 permits authenticated users with the Viewer role or above to exploit the v5 query_range API. By injecting malicious field-key names that contain backticks and quotes, attackers can manipulate the SQL execution context. This results in unauthorized access to ClickHouse SQL commands, enabling them to read sensitive system tables and potentially exfiltrate confidential data. It is crucial for users to update to versions above 0.142.0 to mitigate these risks.
Affected Version(s)
signoz 0.87.0 < 0.142.0
signoz 0.142.0
