PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92729 SigNoz CVE debrief

CVE-2026-92729 debrief based on the supplied source corpus. The CVE record was published on 2026-09-16T19:18:06.833Z and has not been modified since then. SigNoz versions 0.88.0 through 0.141.0 are affected by a vulnerability allowing unauthenticated access to trace-funnel analytics endpoints. This could lead to unauthorized access to sensitive data and disruption of analytics services. Defenders should assess exposure and apply the vendor-provided patch or compensating controls to prevent unauthorized access to trace analytics.

Vendor
SigNoz
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-21
Advisory published
2026-09-16
Advisory updated
2026-09-21

Who should care

Defenders responsible for SigNoz instances, especially those with publicly accessible analytics endpoints, should assess exposure and apply the vendor-provided patch or compensating controls to prevent unauthorized access to trace analytics.

Why it matters

CVE-2026-92729 allows unauthenticated attackers to access trace-funnel analytics endpoints in SigNoz versions 0.88.0 through 0.141.0, potentially leading to unauthorized access to sensitive data and disruption of analytics services. Defenders should prioritize verifying exposure and applying the vendor-provided patch or compensating controls.

  • Potential unauthorized access to sensitive trace analytics data
  • Possible disruption of analytics services due to arbitrary funnel definitions
  • Need for verification of SigNoz instance exposure and patch application
  • Potential impact on incident response plans due to unauthorized access

Technical summary

SigNoz versions 0.88.0 through 0.141.0 have a vulnerability allowing unauthenticated attackers to submit arbitrary funnel definitions and retrieve trace analytics, including identifiers, durations, span counts, service topology, and error activity. This vulnerability could lead to unauthorized access to sensitive data and disruption of analytics services. The vendor has released a patch in version 0.141.1, and defenders should prioritize verifying exposure and applying the patch or compensating controls to prevent unauthorized access to trace analytics.

Defensive priority

Defenders should prioritize verifying exposure of SigNoz instances, especially those with publicly accessible analytics endpoints, and apply the vendor-provided patch or compensating controls to prevent unauthorized access to trace analytics.

Recommended defensive actions

  • Verify SigNoz instance exposure, especially for publicly accessible analytics endpoints
  • Apply the vendor-provided patch (version 0.141.1) or compensating controls to prevent unauthorized access
  • Monitor for suspicious activity on trace-funnel analytics endpoints
  • Review and update incident response plans to address potential unauthorized access to sensitive data
  • Perform an inventory of SigNoz instances to identify potential exposure
  • Review change management processes to ensure timely application of security patches
  • Track and verify the effectiveness of implemented compensating controls

Evidence notes

The CVE record and source references indicate that SigNoz versions 0.88.0 through 0.141.0 are affected by a vulnerability allowing unauthenticated access to trace-funnel analytics endpoints. The vendor has released a patch in version 0.141.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92729 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92729

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92729 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92729

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.