CVE-2026-97056 | SigNoz up to 0.142.x Session Management reset UpdatePasswordByResetPasswordToken/DeleteUser password recovery

SecurityVulns

A vulnerability categorized as critical has been discovered in SigNoz up to 0.142.x. This issue affects the function UpdatePasswordByResetPasswordToken/DeleteUser of the file /api/v2/factor_password/reset of the component Session Management. Executing a manipulation can lead to weak password recovery.

This vulnerability is registered as CVE-2026-97056. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More