CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6051

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)

CVE-2026-85229 is a stored cross-site scripting (XSS) vulnerability in Apache SkyWalking Booster UI affecting versions 10.2.0 through 10.4.0, representing an incomplete fix of CVE-2025-54057. The vulnerability allows improper neutralization of input during web page generation in dashboard widgets. Apache recommends upgrading to Horizon UI 1.0.0 to resolve the issue.

Why it matters: Organizations running Apache SkyWalking 10.2.0 to 10.4.0 must patch immediately, as stored XSS in the UI can enable attackers to inject malicious scripts affecting all users who access the dashboard.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)

CVE-2026-85229 is a stored cross-site scripting (XSS) vulnerability in Apache SkyWalking Booster UI affecting versions 10.2.0 through 10.4.0, representing an incomplete fix of CVE-2025-54057. The vulnerability allows improper neutralization of input during web page generation in dashboard widgets. Apache recommends upgrading to Horizon UI 1.0.0 to resolve the issue.

Why it matters: Organizations running Apache SkyWalking 10.2.0 to 10.4.0 must patch immediately, as stored XSS in the UI can enable attackers to inject malicious scripts affecting all users who access the dashboard.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary