Cleartext transmission of sensitive information in Apache SkyWalking - CVE-2026-71216

 

Cleartext transmission of sensitive information in Apache SkyWalking - CVE-2026-71216

Published: September 4, 2026


Vulnerability identifier: #VU146942
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-71216
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose the PagerDuty integration routing key.

The vulnerability exists due to cleartext transmission of sensitive information in the PagerDuty alarm hook when sending alarm notifications over HTTP. A remote attacker can intercept the unencrypted initial POST request to disclose the PagerDuty integration routing key.

The initial POST is transmitted before an HTTP redirect response is received.


Affected software

Apache SkyWalking

How to mitigate CVE-2026-71216

Install security update from vendor's website.

Apache SkyWalking - update to 11.0.0

External References

Related Security Bulletins