SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85229

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Apache SkyWalking Booster UI versions 10.2.0 through 10.4.0 are vulnerable to a cross-site scripting (XSS) flaw due to improper input handling during web page generation. This vulnerability could allow attackers to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or session hijacking. Organizations using affected versions should prioritize upgrading to Horizon UI 1.0.0 to mitigate this security risk.

CVE
CVE-2026-85229
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%
Apache

Original NVD Description

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.