CVE-2026-57956
MEDIUMSigNoz 0.130.1 - Cross-Organization Insecure Direct Object Reference in Alert Rules
Title source: cnaDescription
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/signoz-cross-organization-insecure-direct-object-reference-in-alert-rules
Scores
CVSS v3
6.4
EPSS
0.0021
EPSS Percentile
11.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (2)
SigNoz/signoz
< 0.130.1
SigNoz/signoz
< 0.133.0
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026