Cross-Site Scripting Vulnerability in Apache SkyWalking UI
CVE-2026-85229
Currently unrated
What is CVE-2026-85229?
The Apache SkyWalking UI versions 10.2.0 through 10.4.0 contain a vulnerability that allows for improper neutralization of input during web page generation, leading to cross-site scripting (XSS) issues. This can allow attackers to execute arbitrary scripts in the context of the user's browser. Users are strongly advised to upgrade to Horizon UI 1.0.0, which effectively addresses this security flaw.
Affected Version(s)
Apache SkyWalking 10.2.0 <= 10.4.0