Description
** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI.



This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0.



Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.
Published: 2026-09-04
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Upgrade UI
AI Analysis

Impact

Improper neutralization of user input during web page generation in the Apache SkyWalking Booster UI dashboard widgets leads to stored cross‑site scripting. When malicious content is persisted within widget configuration data, it is later rendered to other users’ browsers, resulting in the execution of arbitrary client‑side code. This flaw directly corresponds to the CWE‑79 weakness and can enable attackers to run scripts in the context of users interacting with the dashboard.

Affected Systems

The vulnerability affects Apache SkyWalking UI versions 10.2.0 through 10.4.0, shipped by the Apache Software Foundation. It relates specifically to the dashboard’s widget configuration and rendering components. The vendor recommends upgrading to Horizon UI 1.0.0 to eliminate the flaw.

Risk and Exploitability

The CVSS score is 6.1, the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalogue. The flaw can be triggered by any user who can inject data into widget configurations, or by a remote attacker if the UI is exposed. The risk is moderate, but the potential impact on the user’s browser remains significant. Prompt remediation is recommended to mitigate any exploitation risk.

Generated by OpenCVE AI on September 10, 2026 at 04:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SkyWalking UI to Horizon UI 1.0.0 immediately.
  • If an upgrade is not possible, restrict widget configuration to trusted users or disable widget creation for untrusted users.
  • Implement server‑side input validation and output encoding for all widget data until the official fix is applied.

Generated by OpenCVE AI on September 10, 2026 at 04:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache skywalking
Vendors & Products Apache
Apache skywalking

Fri, 04 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.
Title Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
Weaknesses CWE-79
References

Subscriptions

Apache Skywalking
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-08T18:57:06.433Z

Reserved: 2026-09-03T14:47:23.119Z

Link: CVE-2026-85229

cve-icon Vulnrichment

Updated: 2026-09-08T18:57:03.475Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T08:17:16.813

Modified: 2026-09-08T19:20:07.457

Link: CVE-2026-85229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')