Insufficient Session Expiration in SigNoz by SigNoz
CVE-2026-97056

7.6HIGH

Key Information:

Vendor

Signoz

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-97056?

The SigNoz application, prior to version 0.143.0, has an insufficient session expiration vulnerability. When users reset their passwords or are deleted, existing login sessions remain active due to the failure to revoke session tokens. This vulnerability allows attackers with valid session tokens, potentially from stolen sessions or accounts being offboarded, to access the account until tokens expire or rotate. Consequently, this undermines the effectiveness of password resets and user deletions, leaving accounts at risk unless properly addressed.

Affected Version(s)

signoz 0.98.0 < 0.143.0

signoz 0.143.0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.