CVE-2026-57956

SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
Configurations

No configuration.

History

20 Jul 2026, 16:17

Type Values Removed Values Added
Summary (en) SigNoz through 0.130.1 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls. (en) SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
References
  • () https://github.com/SigNoz/signoz/pull/12117 -
  • () https://github.com/SigNoz/signoz/releases/tag/v0.133.0 -

29 Jun 2026, 20:17

Type Values Removed Values Added
References () https://github.com/SigNoz/signoz/issues/11830 - () https://github.com/SigNoz/signoz/issues/11830 -

29 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-29 18:16

Updated : 2026-07-20 16:17


NVD link : CVE-2026-57956

Mitre link : CVE-2026-57956

CVE.ORG link : CVE-2026-57956


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key