Description
** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI.



This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0.



Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.
Published: 2026-09-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation in the Booster UI dashboard widgets allows a stored cross‑site scripting attack. When a malicious script is persisted in the widget data and later rendered to other users, it executes within the victim’s browser context, granting the attacker the victim’s privileges. This can lead to session hijacking, data theft, defacement, or other malicious actions that require the viewer’s level of access.

Affected Systems

The vulnerability exists in Apache SkyWalking UI versions 10.2.0 through 10.4.0. It is shipped by the Apache Software Foundation and affects the web dashboard’s widget configuration and rendering components. The vendor recommends upgrading to Horizon UI 1.0.0 to eliminate the flaw.

Risk and Exploitability

No CVSS or EPSS score is disclosed and the vulnerability is not listed in the CISA KEV catalogue. However, stored XSS is a well‑known high‑risk weakness that can be triggered by any user who can inject data into widget configurations, or by a remote attacker if the UI is exposed. Until the upgrade to Horizon UI 1.0.0 is performed, the risk of cross‑site script execution remains significant and should be treated as high.

Generated by OpenCVE AI on September 4, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SkyWalking UI to Horizon UI 1.0.0 immediately.
  • If an immediate upgrade is not possible, restrict or disable widget configuration for untrusted users and block access to the dashboard from external hosts.
  • Implement server‑side validation and output encoding for all widget content to mitigate injection until the final fix is in place.

Generated by OpenCVE AI on September 4, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache skywalking
Vendors & Products Apache
Apache skywalking

Fri, 04 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.
Title Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
Weaknesses CWE-79
References

Subscriptions

Apache Skywalking
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-04T07:01:39.869Z

Reserved: 2026-09-03T14:47:23.119Z

Link: CVE-2026-85229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T08:17:16.813

Modified: 2026-09-04T08:17:16.813

Link: CVE-2026-85229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T08:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')