CVE-2026-85499: Apache SkyWalking BanyanDB: Canopy does not enforce readonly-role restrictions on the /monitoring/* proxy
Low-severity CVE-2026-85499 lets readonly Apache SkyWalking BanyanDB users proxy non-read monitoring requests.
Apache disclosed CVE-2026-85499, a low-severity improper-authorization flaw in SkyWalking BanyanDB Canopy. Versions 0.11.0 before 0.11.1 ship incomplete proof-of-concept role and monitoring-proxy functionality. If a readonly Canopy user is configured and a monitoring target is reachable, that user can send non-read requests through the /monitoring/* proxy. The oss-security note does not report in-the-wild exploitation.
28