CVE-2026-63094

HIGH

SigNoz 0.133.0 SSO OAuth State Manipulation Session Token Theft

Title source: cna
STIX 2.1

Description

SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.

References (6)

Core 6
Core References
Exploit technical-description exploit
Researcher Disclosure
https://github.com/SigNoz/signoz/issues/11746
Issue Tracking issue-tracking
Pull Request
https://github.com/SigNoz/signoz/pull/11844
Issue Tracking issue-tracking
Pull Request
https://github.com/SigNoz/signoz/pull/12172
Release Notes release-notes
Release Notes
https://github.com/SigNoz/signoz/releases/tag/v0.134.0

Scores

CVSS v3 8.1
EPSS 0.0017
EPSS Percentile 6.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-345 CWE-601
Status published
Products (3)
SigNoz/signoz < 0.133.0
SigNoz/signoz < 0.134.0
SigNoz/signoz 253ca7dd7eb4f7a32a694c249eb0d5d0804d5619
Published Jul 17, 2026
Tracked Since Jul 17, 2026