Cross-site scripting in Apache SkyWalking - CVE-2026-85229
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in Apache SkyWalking Booster UI dashboard widgets when rendering dashboard widgets. A remote attacker can store crafted script content in dashboard widgets to execute arbitrary script in a victim's browser.