CVE-2026-93426

Published: Set 18, 2026 Last Modified: Set 22, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,4
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 8,5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: low
Availability: none

Description

AI Translation Available

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.

89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Stable
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Availability Authentication Access Control
Potential Impacts:
Execute Unauthorized Code Or Commands Read Application Data Gain Privileges Or Assume Identity Bypass Protection Mechanism Modify Application Data
Applicable Platforms
Languages: Not Language-Specific, SQL
Technologies: Database Server
View CWE Details
https://github.com/SigNoz/signoz/security/advisories/GHSA-q3h7-gpc9-2rxc
https://github.com/SigNoz/signoz
https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/apiserver/signozapiserver/qu…
https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/querybuilder/fallback_expr.g…
https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/telemetrymetadata/field_mapp…
https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d
https://github.com/SigNoz/signoz/commit/9c886be12015c43a1465af3532b3c3afbec6bebc
https://github.com/SigNoz/signoz/releases/tag/v0.142.0
https://github.com/SigNoz/signoz/security/advisories/GHSA-q3h7-gpc9-2rxc
https://www.vulncheck.com/advisories/signoz-0.87.0-before-0.142.0-sql-injection…