CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
Published Sep 4, 2026
·Updated
UNSUPPORTED WHEN ASSIGNED Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI.
This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0.
Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.
Affected Software
1 affected component
Apache SkyWalking UI (Booster UI)>=10.2.0<=10.4.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache SkyWalking Booster UI / Horizon UIto a version that resolves this vulnerability.Fixed in 1.0.0
Event History
Sep 4, 2026
CVE Published
via MITRE·07:01 AM
Data Sourced
via MITRE·07:01 AM
DescriptionWeakness