External risk intelligence

SigNoz Authentication Bypass Via Empty JWT Secret.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-97055

SigNoz is an observability and monitoring platform that provides a web-based dashboard for application performance management. Such platforms are commonly deployed as web applications accessible to users across an organization, frequently leading to them being hosted on network-accessible infrastructure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in SigNoz, an observability platform, where an empty signing secret for session tokens could allow an unauthenticated attacker to impersonate existing users, including administrators. This could enable unauthorized access and control over the platform's functionalities and data.

  • Unauthenticated users can impersonate others.
  • This bypasses access controls for sensitive data.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by leveraging the default configuration of an affected SigNoz deployment. Since the JWT signing secret defaults to an empty string and isn't validated, an unauthenticated attacker can forge a session token for any user, including administrators, by using the user's ID, organization ID, and email. These details can be retrieved without authentication from a public API endpoint. The forged token can then be used to obtain new, unrevocable session tokens, granting persistent access.

  • Attacker needs no authentication to start.
  • Attacker forges a session token using leaked info.
  • Unauthenticated access leads to persistent session control.

Live Threat

Current exploitation, exposure, and threat context

When SigNoz is deployed without a configured JWT secret, an unauthenticated attacker can forge session tokens for existing users, including administrators, by leveraging an empty signing key. This allows the attacker to impersonate users and gain unauthorized access to the platform.

  • User and administrator session data
  • Forged session tokens can be created.
  • Unauthorized access to the platform.

Operational Fix

Recommended remediation, mitigation, and detection steps

In a typical deployment, SigNoz observability platforms are managed by platform or infrastructure teams responsible for their operational health. Given the critical nature of this authentication bypass, the first practical step is to identify all SigNoz instances, confirm their network exposure and business criticality, and then engage the accountable owners to plan remediation.

  • Platform or Infrastructure teams own remediation.
  • Verify SigNoz instances and network exposure.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SigNoz and how is it used?

SigNoz is an open-source observability and monitoring platform. It collects application performance data, logs, and metrics into a centralized web-based dashboard, allowing teams to analyze system health, trace requests, and troubleshoot complex application issues in real-time.

What does CVE-2026-97055 mean for security?

This vulnerability is classified as CWE-1188, which involves the use of insecure default settings. In this case, the system defaults to an empty string for the secret key used to sign session tokens. Because the software fails to reject this empty value, anyone can create their own valid session tokens by signing them with that same empty key, effectively bypassing authentication.

How does an attacker trigger this vulnerability?

An attacker needs no special access to begin. They can retrieve necessary user details, such as organization IDs and email addresses, from an unauthenticated API endpoint. Once they have this information, they can manually forge a session token signed with the empty key. Note that this bug only occurs if the system is running with the default, unconfigured JWT secret; if a unique secret is manually set, this specific forgery path does not work.

Is my deployment at risk?

According to Halo Surface Signal, this vulnerability is most relevant if your SigNoz instance is network-accessible. Because these platforms are often deployed as web applications intended for broad internal use, they are frequently hosted on infrastructure that could be reached by unauthorized parties. You should evaluate whether your instance is exposed to the internet or accessible from untrusted network segments.

How do I secure my SigNoz instance?

Your first step is to verify the configuration of all deployed SigNoz instances to confirm if they are using the default JWT secret. If you are running a version earlier than v0.143.0, you must update the software. The latest version corrects this by requiring a valid, non-empty secret when the JWT provider is selected and updates the default provider to use opaque tokens instead.

References