CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CVE-2026-85499: Apache SkyWalking BanyanDB: Canopy does not enforce readonly-role restrictions on the /monitoring/* proxy

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8743

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-85499: Apache SkyWalking BanyanDB: Canopy does not enforce readonly-role restrictions on the /monitoring/* proxy

CVE-2026-85499 affects Apache SkyWalking BanyanDB 0.11.0 before 0.11.1, where the Canopy component fails to enforce read-only role restrictions on the /monitoring/* proxy endpoint. A read-only user on a non-default configuration can send write requests through the monitoring proxy if the target is reachable. The vulnerability has a low severity rating.

Why it matters: Organizations running BanyanDB with Canopy and non-default read-only role configurations should upgrade to 0.11.1 to prevent privilege escalation by restricted users performing unauthorized write operations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary