SQL Injection Vulnerability in SigNoz by SigNoz
CVE-2026-93426

8.4HIGH

Key Information:

Vendor

Signoz

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-93426?

A security flaw in SigNoz versions prior to 0.142.0 permits authenticated users with the Viewer role or above to exploit the v5 query_range API. By injecting malicious field-key names that contain backticks and quotes, attackers can manipulate the SQL execution context. This results in unauthorized access to ClickHouse SQL commands, enabling them to read sensitive system tables and potentially exfiltrate confidential data. It is crucial for users to update to versions above 0.142.0 to mitigate these risks.

Affected Version(s)

signoz 0.87.0 < 0.142.0

signoz 0.142.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alexwaira
tonghuaroot
dodge1218
456789TZ
.