As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-85499: Apache SkyWalking BanyanDB: Canopy does not enforce readonly-role restrictions on the /monitoring/* proxy
CVE-2026-85499 affects Apache SkyWalking BanyanDB 0.11.0 before 0.11.1, where the Canopy component fails to enforce read-only role restrictions on the /monitoring/* proxy endpoint. A read-only user on a non-default configuration can send write requests through the monitoring proxy if the target is reachable. The vulnerability has a low severity rating.
Why it matters: Organizations running BanyanDB with Canopy and non-default read-only role configurations should upgrade to 0.11.1 to prevent privilege escalation by restricted users performing unauthorized write operations.
- Source published
- First seen by Cybersecurity Tracker