Insufficient Session Expiration in SigNoz by SigNoz
CVE-2026-97056
7.6HIGH
What is CVE-2026-97056?
The SigNoz application, prior to version 0.143.0, has an insufficient session expiration vulnerability. When users reset their passwords or are deleted, existing login sessions remain active due to the failure to revoke session tokens. This vulnerability allows attackers with valid session tokens, potentially from stolen sessions or accounts being offboarded, to access the account until tokens expire or rotate. Consequently, this undermines the effectiveness of password resets and user deletions, leaving accounts at risk unless properly addressed.
Affected Version(s)
signoz 0.98.0 < 0.143.0
signoz 0.143.0
