CVE-2026-93426
HIGH
8,4
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
8,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: low
Availability: none
Description
AI Translation Available
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.
89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
StableCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Authentication
Access Control
Potential Impacts:
Execute Unauthorized Code Or Commands
Read Application Data
Gain Privileges Or Assume Identity
Bypass Protection Mechanism
Modify Application Data
Applicable Platforms
Languages:
Not Language-Specific, SQL
Technologies:
Database Server
https://github.com/SigNoz/signoz/security/advisories/GHSA-q3h7-gpc9-2rxc
https://github.com/SigNoz/signoz
https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/apiserver/signozapiserver/qu…
https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/querybuilder/fallback_expr.g…
https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/telemetrymetadata/field_mapp…
https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d
https://github.com/SigNoz/signoz/commit/9c886be12015c43a1465af3532b3c3afbec6bebc
https://github.com/SigNoz/signoz/releases/tag/v0.142.0
https://github.com/SigNoz/signoz/security/advisories/GHSA-q3h7-gpc9-2rxc
https://www.vulncheck.com/advisories/signoz-0.87.0-before-0.142.0-sql-injection…