Back Redpacketsecurity CVE Alert: CVE-2026-93292 – SigNoz
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
## AI Summary Analysis
**Risk verdict:** High risk for exposed deployments; prioritise urgently, although KEV status, SSVC exploitation state, PoC availability and EPSS are not provided, so active exploitation cannot be confirmed.
**Why this matters:** A low-privilege authenticated user may be able to make the analytics backend return sensitive telemetry and associated operational data. This could expose service topology, customer activity, credentials or tokens captured in traces, while limited write impact could assist tampering and follow-on intrusion.
**Most likely attack path:** An attacker reaches the application over the network, authenticates with any account permitted to view trace analytics, and submits crafted funnel parameters; low complexity and no user interaction make exploitation practical. The changed scope indicates potential impact beyond the vulnerable service, particularly where the analytics database contains cross-tenant or production telemetry and trusts surrounding systems.
**Who is most exposed:** Internet-facing or partner-accessible SigNoz instances, especially shared observability platforms, self-hosted deployments with broad viewer access, and environments retaining sensitive headers or request data in traces.
Review analytics requests for unusual quoting, , operators or encoded SQL metacharacters in funnel fields.
Alert on anomalous query latency, errors, result sizes and ClickHouse statements from the query service.
Correlate newly created or abused low-privilege accounts with trace-data exports.
Hunt access logs for repeated requests across funnel routes and unusual response volumes.
Mitigation and prioritisation:
Upgrade to the complete fixed release; do not rely on the intermediate partial fix.
Until change approval, restrict analytics access, remove internet exposure and enforce VPN or identity-aware proxy controls.
Rotate secrets appearing in telemetry and review historical access for bulk reads.
Validate tenant isolation and apply least privilege; test the upgrade in staging because query behaviour may change.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
