CVE-2026-85499: Apache SkyWalking BanyanDB: Canopy does not enforce readonly-role restrictions on the /monitoring/* proxy
Low-severity CVE-2026-85499 lets readonly Apache SkyWalking BanyanDB users proxy non-read monitoring requests.
Apache disclosed CVE-2026-85499, a low-severity improper-authorization flaw in SkyWalking BanyanDB Canopy. Versions 0.11.0 before 0.11.1 ship incomplete proof-of-concept role and monitoring-proxy functionality. If a readonly Canopy user is configured and a monitoring target is reachable, that user can send non-read requests through the /monitoring/* proxy. The oss-security note does not report in-the-wild exploitation.
- CVE-2026-85499 is rated low and requires a non-default configuration.
- A readonly Canopy user can send non-read requests through /monitoring/*.
- Apache SkyWalking BanyanDB 0.11.0 is affected; 0.11.1 fixes it.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85499 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by Hongtao Gao on Sep 28 Severity: low Affected versions: - Apache SkyWalking BanyanDB 0.11.0 before 0.11.1 Description: Improper Authorization vulnerability in Apache SkyWalking BanyanDB. The Canopy includes incomplete proof-of-concept role and monitoring-proxy functionality. Under a non-default configuration with a readonly Canopy user and a reachable monitoring target, that user can send non-read requests through the monitoring proxy. This issue affects...
This source does not provide full text. Read it at seclists.org.