CVE-2026-57956

MEDIUM

SigNoz 0.130.1 - Cross-Organization Insecure Direct Object Reference in Alert Rules

Title source: cna
STIX 2.1

Description

SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.

References (4)

Core 4
Core References
Issue Tracking issue-tracking
Researcher Disclosure
https://github.com/SigNoz/signoz/issues/11830
Release Notes release-notes
Release Notes
https://github.com/SigNoz/signoz/releases/tag/v0.133.0
Issue Tracking issue-tracking
Pull Request
https://github.com/SigNoz/signoz/pull/12117

Scores

CVSS v3 6.4
EPSS 0.0021
EPSS Percentile 11.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
SigNoz/signoz < 0.130.1
SigNoz/signoz < 0.133.0
Published Jun 29, 2026
Tracked Since Jun 29, 2026