CVE-2026-97056
📛 CVE Title
SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass
Description
SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is reset with a reset token (UpdatePasswordByResetPasswordToken, reachable via POST /api/v2/factor_password/reset) or when the user is deleted (DeleteUser, reachable via DELETE /api/v2/users/{id}). Neither code path calls the tokenizer's DeleteTokensByUserID, so cached tokens and identities are left in place. An attacker who already holds a session token for the account — for example from a stolen browser session or from a user being offboarded — retains the account's full access, up to administrator, after a password reset until the token reaches its configured maximum lifetime (30 days by default), and after user deletion until the token next rotates (30 minutes by default). This defeats password reset and user deletion as a means of terminating access. The issue is fixed in v0.143.0.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulnCheck
- CVSS severity
- HIGH
- CVSS score
- 7.6 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N- Effective score
- 7.6 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-613 - Reserved
- 2026-09-23
- Published
- 2026-09-24 01:53 UTC
- Last updated
- 2026-09-24 12:56 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/97xxx/CVE-2026-97056.json
- Linked Threat
- CVE-2026-97056 — SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- EPSS score
- 0.0035 (probability of exploitation in next 30 days)
- EPSS percentile
- 25.80% vs all CVEs — higher = more likely to be exploited, as of 2026-09-24
NVD / KEV / EPSS data refreshed 2026-09-25 04:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85773 - Assigner
- VulnCheck
- Published
- Sep 24, 2026, 1:53:04 AM
- Updated
- Sep 24, 2026, 12:56:55 PM
- EUVD base score (CVSS 4.0)
-
7.6 / 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.3500
- Vendors
- SigNoz
- Products
-
signoz (0.98.0 <0.143.0)
- Aliases
-
GHSA-r949-5536-p6gg
ENISA description: SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is reset with a reset token (UpdatePasswordByResetPasswordToken, reachable via POST /api/v2/factor_password/reset) or when the user is deleted (DeleteUser, reachable via DELETE /api/v2/users/{id}). Neither code path calls the tokenizer's DeleteTokensByUserID, so cached tokens and identities are left in place. An attacker who already holds a session token for the account — for example from a stolen browser session or from a user being offboarded — retains the account's full access, up to administrator, after a password reset until the token reaches its configured maximum lifetime (30 days by default), and after user deletion until the token next rotates (30 minutes by default). This defeats password reset and user deletion as a means of terminating access. The issue is fixed in v0.143.0.
EUVD references (6)
- https://github.com/SigNoz/signoz/security/advisories/GHSA-xrgp-3fq4-xg83
- https://github.com/SigNoz/signoz/commit/faaed20dbd
- https://github.com/SigNoz/signoz/commit/e2e9173986
- https://github.com/SigNoz/signoz/commit/b02aae2db3
- https://github.com/SigNoz/signoz/commit/c122bc09b4
- https://www.vulncheck.com/advisories/signoz-before-0.143.0-insufficient-session-expiration-authentication-bypass
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| SigNoz | signoz |
0.98.0 (affected),
0.143.0 (unaffected)
|
— |
Vendor references (6)
References embedded in the original CVE record by the assigning CNA.
- GitHub Security Advisory (GHSA-xrgp-3fq4-xg83) vendor-advisory
- Patch Commit patch
- Patch Commit patch
- Patch Commit patch
- Patch Commit patch
- VulnCheck Advisory: SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass third-party-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:arcticwolf.com
Validate Group Policy and registry settings for Defender to ensure real-time protection, automatic remediation , and exclusion policies are secured. Temporary Workarounds Block Vulnerable Apps: Use Microsoft Defender Vulnerability Management to block or warn against execution of affected binaries for systems pending a patch .
2026-09-25 10:08 UTC -
web:blog.qualys.com
Key Takeaways RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM access No patch is currently available, leaving all Defender-enabled Windows systems potentially exposed Qualys VMDR detects affected assets instantly (QID 92382) TruRisk™ Eliminate enables immediate mitigation , removing exploitability without waiting for a fix ...
2026-09-25 10:08 UTC -
web:cvetodo.com
CVE-2026-97056 is a CVSS 6.8 medium-severity vulnerability in SigNoz. Full technical analysis, mitigations , and exploit status — updated in real time.
2026-09-25 10:08 UTC -
web:cybernews.com
Microsoft's latest Patch Tuesday addressed 236 Windows bugs, only for the disgruntled researcher Nightmare Eclipse to show up and punch a massive privilege escalation hole. It isn't even new - the Windows Defender exploit bypasses the previous insufficient fix .
2026-09-25 10:08 UTC -
web:dailysecurityreview.com
Microsoft confirmed CVE - 2026 -50656, a zero-day in the Defender Malware Protection Engine allowing SYSTEM-level privilege escalation, is under active exploitation with no patch currently available.
2026-09-25 10:08 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-25 10:08 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-09-25 10:08 UTC -
web:patchmypc.com
You can find the production release history below for 2026 .
2026-09-25 10:08 UTC -
web:www.cisecurity.org
Microsoft reports CVE - 2026 -56164 has been exploited in the wild. CVE - 2026 -56164 may allow remote cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. Microsoft noted that integrating its Antimalware Scan Interface (AMSI) can provide temporary mitigation by actively scanning and detecting malicious POST requests associated with exploitation attempts. The ...
2026-09-25 10:08 UTC -
web:www.malwarebytes.com
The RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.
2026-09-25 10:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-97056.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97056",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T12:55:59.241523Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T12:56:55.730Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-xrgp-3fq4-xg83"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.143.0",
"status": "affected",
"version": "0.98.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.143.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is reset with a reset token (UpdatePasswordByResetPasswordToken, reachable via POST /api/v2/factor_password/reset) or when the user is deleted (DeleteUser, reachable via DELETE /api/v2/users/{id}). Neither code path calls the tokenizer's DeleteTokensByUserID, so cached tokens and identities are left in place. An attacker who already holds a session token for the account \u2014 for example from a stolen browser session or from a user being offboarded \u2014 retains the account's full access, up to administrator, after a password reset until the token reaches its configured maximum lifetime (30 days by default), and after user deletion until the token next rotates (30 minutes by default). This defeats password reset and user deletion as a means of terminating access. The issue is fixed in v0.143.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-613",
"description": "Insufficient Session Expiration",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T01:53:04.486Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-xrgp-3fq4-xg83)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-xrgp-3fq4-xg83"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/faaed20dbd"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/e2e9173986"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/b02aae2db3"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/c122bc09b4"
},
{
"name": "VulnCheck Advisory: SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-before-0.143.0-insufficient-session-expiration-authentication-bypass"
}
],
"title": "SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-97056",
"datePublished": "2026-09-24T01:53:04.486Z",
"dateReserved": "2026-09-23T23:51:32.670Z",
"dateUpdated": "2026-09-24T12:56:55.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}