dash0 Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Overview

Welcome to our Trust Center. At Dash0, your security, privacy, and trust are our top priorities. Here, you'll find information on how we protect your data, comply with regulations, and uphold ethical standards. We are dedicated to creating a secure and reliable environment for you.

Documents

REPORTSNetwork Diagram

Trust Center Updates

Security Updates

Copy link
General

Vulnerability Affecting Dash0

Affected customers were notified directly on June 19, 2026.

On June 18, 2026, Dash0 identified and resolved a security vulnerability affecting ingest-only auth tokens.

We have not found evidence of successful exploitation but recommend rotating any credentials accessible through publicly exposed ingest-only tokens related to synthetic API checks and notification channels, and reviewing your audit logs for suspicious activity.

Credentials stored in integrations as well as telemetry data have not been affected by this vulnerability.


What Happened

On June 18 at 14:53 UTC, we were notified by an external security researcher of an exposed auth token that could be used to access tenant configurations beyond its intended scope. Upon investigation, we identified a vulnerability in our permission validation logic — ingest-only auth tokens, intended solely for sending telemetry data, had unintended read and write access to tenant configurations, including notification channels, check rules, dashboards, and teams.

We confirmed and contained the initial report by 15:35 UTC the same day and deployed a full fix by 18:24 UTC. We have confirmed the issue is fully resolved.


Who Is Affected

This vulnerability applies to ingest-only auth tokens that were publicly exposed — for example, embedded in frontend code or public repositories. If your ingest-only tokens were kept private and treated like any other write-enabled token, your risk is minimal.

We reviewed audit logs for all affected tokens and found no evidence of malicious activity.

Credentials stored in integrations as well as telemetry data have not been affected by this vulnerability.


What You Should Do

If you have ingest-only tokens that were publicly exposed:

  • Review any credentials accessible through your ingest-only token — including those stored in synthetic API checks and notification channels — and rotate those as a precaution.
  • Review your audit logs for any unexpected activity.
    If you are seeing broken workflows (e.g. operator deployments, CLI or Terraform provider usage) following our fix shipped on June 18: create a new token with the exact permissions your workflow requires. That will resolve it immediately.

If you are unsure whether you are affected, reach out to security@dash0.com and we will help you check.


What We've Done

  • June 18, 15:35 UTC — Disabled the initially reported token and RCA kicked off.
  • June 18, 17:04 UTC — Reviewed access logs and found no evidence of malicious use of affected ingest-only customer tokens.
  • June 18, 18:24 UTC — Deployed a fix across all API endpoints.
  • June 19, 12:30 UTC — Proactively reached out to customers known to be impacted.
  • June 25, 11:20 UTC — Published to trust center.

A full root cause analysis is underway and we are evaluating additional controls to detect and prevent similar misconfigurations before they reach production.


Gratitude

We'd like to thank Nickita Khylkouski from Peak Security for responsibly disclosing this finding.

If you have any questions, reach out to security@dash0.com.

Built onSafeBase by Drata Logo