Severity: low 

Affected versions:

- Apache SkyWalking BanyanDB 0.11.0 before 0.11.1

Description:

Improper Authorization vulnerability in Apache SkyWalking BanyanDB.



The Canopy includes incomplete proof-of-concept role and monitoring-proxy 
functionality. Under a non-default configuration with a readonly Canopy user 
and a reachable monitoring target, that user can send non-read requests through 
the monitoring proxy.



This issue affects Apache SkyWalking BanyanDB: from 0.11.0 before 0.11.1.



Users are recommended to upgrade to version 0.11.1, which fixes the issue.

References:

https://skywalking.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-85499

Reply via email to