PatchSiren cyber security CVE debrief
CVE-2026-92729 SigNoz CVE debrief
CVE-2026-92729 debrief based on the supplied source corpus. The CVE record was published on 2026-09-16T19:18:06.833Z and has not been modified since then. SigNoz versions 0.88.0 through 0.141.0 are affected by a vulnerability allowing unauthenticated access to trace-funnel analytics endpoints. This could lead to unauthorized access to sensitive data and disruption of analytics services. Defenders should assess exposure and apply the vendor-provided patch or compensating controls to prevent unauthorized access to trace analytics.
- Vendor
- SigNoz
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for SigNoz instances, especially those with publicly accessible analytics endpoints, should assess exposure and apply the vendor-provided patch or compensating controls to prevent unauthorized access to trace analytics.
Why it matters
CVE-2026-92729 allows unauthenticated attackers to access trace-funnel analytics endpoints in SigNoz versions 0.88.0 through 0.141.0, potentially leading to unauthorized access to sensitive data and disruption of analytics services. Defenders should prioritize verifying exposure and applying the vendor-provided patch or compensating controls.
- Potential unauthorized access to sensitive trace analytics data
- Possible disruption of analytics services due to arbitrary funnel definitions
- Need for verification of SigNoz instance exposure and patch application
- Potential impact on incident response plans due to unauthorized access
Technical summary
SigNoz versions 0.88.0 through 0.141.0 have a vulnerability allowing unauthenticated attackers to submit arbitrary funnel definitions and retrieve trace analytics, including identifiers, durations, span counts, service topology, and error activity. This vulnerability could lead to unauthorized access to sensitive data and disruption of analytics services. The vendor has released a patch in version 0.141.1, and defenders should prioritize verifying exposure and applying the patch or compensating controls to prevent unauthorized access to trace analytics.
Defensive priority
Defenders should prioritize verifying exposure of SigNoz instances, especially those with publicly accessible analytics endpoints, and apply the vendor-provided patch or compensating controls to prevent unauthorized access to trace analytics.
Recommended defensive actions
- Verify SigNoz instance exposure, especially for publicly accessible analytics endpoints
- Apply the vendor-provided patch (version 0.141.1) or compensating controls to prevent unauthorized access
- Monitor for suspicious activity on trace-funnel analytics endpoints
- Review and update incident response plans to address potential unauthorized access to sensitive data
- Perform an inventory of SigNoz instances to identify potential exposure
- Review change management processes to ensure timely application of security patches
- Track and verify the effectiveness of implemented compensating controls
Evidence notes
The CVE record and source references indicate that SigNoz versions 0.88.0 through 0.141.0 are affected by a vulnerability allowing unauthenticated access to trace-funnel analytics endpoints. The vendor has released a patch in version 0.141.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92729 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92729
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92729 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92729
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/SigNoz/signoz
-
Source reference
Unverified legacy reference
URL: https://github.com/SigNoz/signoz/blob/v0.141.0/pkg/query-service/app/http_handler.go
-
Source reference
Unverified legacy reference
URL: https://github.com/SigNoz/signoz/commit/f78bd492d8732f011bc96837cf9862db2df0783d
-
Source reference
Unverified legacy reference
URL: https://github.com/SigNoz/signoz/pull/12817
-
Source reference
Unverified legacy reference
URL: https://github.com/SigNoz/signoz/releases/tag/v0.141.1
-
Source reference
Unverified legacy reference
URL: https://github.com/SigNoz/signoz/security/advisories/GHSA-v549-7j2x-qjm5
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/signoz-0.88.0-through-0.141.0-missing-authentication-on-trace-funnel-analytics-endpoints
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.