Redpacketsecurity Critical SQL Injection and Authorization Bypass Vulnerabilities Disclosed
Article Content
- •CVE-2026-93292 allows SQL injection in SigNoz, risking sensitive data exposure.
- •CVE-2026-92753 enables authorization bypass in PatrowlManager, affecting user alerts.
- •Both vulnerabilities are high-risk for internet-facing deployments and require urgent patching.
Two significant vulnerabilities have been disclosed affecting SigNoz and PatrowlManager. CVE-2026-93292 in SigNoz versions 0.88.0 to 0.142.1 allows low-privilege authenticated users to exploit SQL injection in trace-funnel analytics endpoints. This could lead to unauthorized access to sensitive telemetry and operational data. CVE-2026-92753 in PatrowlManager versions up to 1.8.4 permits authenticated attackers to bypass authorization, enabling them to read, delete, and modify alerts and events of other users. Both vulnerabilities are high-risk for internet-facing deployments, with exploitation paths requiring minimal effort and no elevated privileges. Current status indicates no confirmed active exploitation for either CVE, but urgent remediation is advised due to the potential impact on sensitive data and user trust.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-92753 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…