{"id":"CVE-2026-92729","summary":"SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints","details":"SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.","aliases":["GHSA-v549-7j2x-qjm5"],"modified":"2026-09-18T03:48:44.977509874Z","published":"2026-09-16T18:31:19.245Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-306","CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92729.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92729.json"},{"type":"ADVISORY","url":"https://github.com/SigNoz/signoz/releases/tag/v0.141.1"},{"type":"ADVISORY","url":"https://github.com/SigNoz/signoz/security/advisories/GHSA-v549-7j2x-qjm5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92729"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/signoz-0.88.0-through-0.141.0-missing-authentication-on-trace-funnel-analytics-endpoints"},{"type":"FIX","url":"https://github.com/SigNoz/signoz/commit/f78bd492d8732f011bc96837cf9862db2df0783d"},{"type":"FIX","url":"https://github.com/SigNoz/signoz/pull/12817"},{"type":"PACKAGE","url":"https://github.com/SigNoz/signoz"},{"type":"ARTICLE","url":"https://github.com/SigNoz/signoz/blob/v0.141.0/pkg/query-service/app/http_handler.go#L4073-L4086"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/signoz/signoz","events":[{"introduced":"9a3a8c8305b8ca9e493e0b12bc19db47775bc809"},{"fixed":"f78bd492d8732f011bc96837cf9862db2df0783d"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0.88.0"},{"fixed":"0.141.1"}]}}],"versions":["v0.141.0","v0.140.0","v0.139.0","v0.138.0","v0.137.1","v0.137.0","v0.136.1","v0.135.1","v0.136.0","v0.135.0-cloud.5","v0.135.0","v0.135.0-cloud.4","v0.135.0-cloud.3","v0.135.0-cloud.2","v0.135.0-cloud.1","v0.134.0","v0.134.0-cloud.2","v0.134.0-cloud.1","v0.133.0","v0.132.2","v0.132.1","v0.132.0","v0.131.1","v0.132.0-rc.2","v0.132.0-rc.1","v0.131.0","v0.130.1","v0.130.0","v0.129.0","v0.128.0","v0.127.1","v0.127.0","v0.126.3-rc.1","v0.126.1","v0.126.0","v0.125.1","v0.125.0","v0.124.0","v0.123.0","v0.122.0","v0.121.1","v0.121.0","v0.120.0","v0.119.0","v0.118.0","v0.117.1","v0.117.0","v0.116.0","v0.116.1","v0.115.0","v0.114.1","v0.114.0","v0.113.0","v0.113.0-rc.1","v0.112.1","v0.112.0","v0.111.0","v0.110.1","v0.110.0","v0.109.3","v0.109.2","v0.109.1","v0.109.0","v0.108.0","v0.108.0-rc.1","v0.107.0","v0.106.0","v0.105.1","v0.105.0","v0.104.0","v0.104.0-cloud.1","v0.103.1","v0.103.0","v0.102.1","v0.102.0","v0.101.0","v0.101.0-rc.1","v0.100.1","v0.100.0","v0.99.0","v0.98.0","v0.98.0-rc.1","v0.98.0-rc.0","v0.97.1","v0.97.0","v0.97.0-rc.3","v0.97.0-rc.2","v0.97.0-rc.1","v0.96.1","v0.96.0","v0.95.1-cloud.1","v0.95.1","v0.95.0","v0.94.1-cloud.1","v0.94.0","v0.94.1","v0.93.0-cloud.3","v0.93.0-cloud.2","v0.93.0-cloud.1","v0.93.0","v0.93.0-rc.1","v0.93.0-rc.3","v0.93.0-rc.2","v0.92.2","v0.92.1","v0.92.0","v0.91.1","v0.92.0-rc.5","v0.92.0-rc.1","v0.92.0-cloud.1","v0.91.0","v0.90.1","v0.90.0","v0.89.0","v0.88.1","v0.88.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92729.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"}]}