Horizon Alert
Summary of the vulnerability and why it matters
A security issue has been identified in SigNoz, an observability platform, where an empty signing secret for session tokens could allow an unauthenticated attacker to impersonate existing users, including administrators. This could enable unauthorized access and control over the platform's functionalities and data.
- Unauthenticated users can impersonate others.
- This bypasses access controls for sensitive data.
- Confirm relevance and potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by leveraging the default configuration of an affected SigNoz deployment. Since the JWT signing secret defaults to an empty string and isn't validated, an unauthenticated attacker can forge a session token for any user, including administrators, by using the user's ID, organization ID, and email. These details can be retrieved without authentication from a public API endpoint. The forged token can then be used to obtain new, unrevocable session tokens, granting persistent access.
- Attacker needs no authentication to start.
- Attacker forges a session token using leaked info.
- Unauthenticated access leads to persistent session control.
Live Threat
Current exploitation, exposure, and threat context
When SigNoz is deployed without a configured JWT secret, an unauthenticated attacker can forge session tokens for existing users, including administrators, by leveraging an empty signing key. This allows the attacker to impersonate users and gain unauthorized access to the platform.
- User and administrator session data
- Forged session tokens can be created.
- Unauthorized access to the platform.
Operational Fix
Recommended remediation, mitigation, and detection steps
In a typical deployment, SigNoz observability platforms are managed by platform or infrastructure teams responsible for their operational health. Given the critical nature of this authentication bypass, the first practical step is to identify all SigNoz instances, confirm their network exposure and business criticality, and then engage the accountable owners to plan remediation.
- Platform or Infrastructure teams own remediation.
- Verify SigNoz instances and network exposure.
- Plan remediation based on confirmed risk.