As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
CVE-2026-85229 is a stored cross-site scripting (XSS) vulnerability in Apache SkyWalking Booster UI affecting versions 10.2.0 through 10.4.0, representing an incomplete fix of CVE-2025-54057. The vulnerability allows improper neutralization of input during web page generation in dashboard widgets. Apache recommends upgrading to Horizon UI 1.0.0 to resolve the issue.
Why it matters: Organizations running Apache SkyWalking 10.2.0 to 10.4.0 must patch immediately, as stored XSS in the UI can enable attackers to inject malicious scripts affecting all users who access the dashboard.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
CVE-2026-85229 is a stored cross-site scripting (XSS) vulnerability in Apache SkyWalking Booster UI affecting versions 10.2.0 through 10.4.0, representing an incomplete fix of CVE-2025-54057. The vulnerability allows improper neutralization of input during web page generation in dashboard widgets. Apache recommends upgrading to Horizon UI 1.0.0 to resolve the issue.
Why it matters: Organizations running Apache SkyWalking 10.2.0 to 10.4.0 must patch immediately, as stored XSS in the UI can enable attackers to inject malicious scripts affecting all users who access the dashboard.
- Source published
- First seen by Cybersecurity Tracker