CVE-2026-105707
Received Received - Intake

Information Exposure via Error Message in Uptrace

Vulnerability report for CVE-2026-105707, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulDB

Description

A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
n/a uptrace 2.1.0-beta.0
n/a uptrace 2.1.0-beta.1
n/a uptrace 2.1.0-beta.2
n/a uptrace 2.1.0-beta.3
n/a uptrace 2.1.0-beta.4
n/a uptrace 2.1.0-beta.5
n/a uptrace 2.1.0-beta.6
n/a uptrace 2.1.0-beta.7
n/a uptrace 2.1.0-beta.8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects uptrace versions up to 2.1.0-beta.8. It involves the Login function in pkg/org/user_handler.go, where improper error handling leads to information exposure. Attackers can remotely exploit this by sending incorrect passwords and observing distinct error responses to enumerate valid email addresses.

Detection Guidance

Check Uptrace version with 'uptrace version' or inspect Docker images for versions <= 2.1.0-beta.8. Monitor authentication endpoints for error responses that reveal valid email addresses or excessive signup attempts.

Impact Analysis

An attacker could use this to gather valid email addresses for phishing or credential-stuffing attacks. The vulnerability may also allow resource exhaustion through unlimited account creation without verification, enabling pre-registration of victim identities.

Compliance Impact

The vulnerability allows unauthenticated attackers to enumerate valid email addresses through distinct error responses during login attempts. This could lead to privacy violations under GDPR by exposing personal data (email addresses) without consent. For HIPAA, if the system handles protected health information, unauthorized access to user accounts could compromise confidentiality requirements.

Mitigation Strategies

Upgrade Uptrace to the latest version. Implement standardized error messages to prevent email enumeration. Add rate limiting or CAPTCHA to signup endpoints. Disable open registration in self-hosted setups if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105707. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart