Skip to content
Rota Nacional

Cyber ·

CVE-2026-85499: BanyanDB proxy flaw

A notice published on September 28, 2026 describes a low-severity authorization flaw in Apache SkyWalking BanyanDB 0.11.0. In a non-default configuration, a read-only Canopy user can send non-read requests through the monitoring proxy.

The CVE-2026-85499 notice was published on September 28, 2026, by Hongtao Gao on the oss-sec feed. The supplied text is an automatic translation. It rates the issue low severity and lists Apache SkyWalking BanyanDB 0.11.0, up to but not including 0.11.1, as affected.

According to the description, Canopy includes incomplete proof-of-concept features for roles and a monitoring proxy. In a non-default configuration, if there is a read-only Canopy user and an accessible monitoring target, that user can send non-read requests through the /monitoring/* proxy. The available excerpt does not detail the impact of those requests or provide a fix.

To assess exposure, check the installed version, the Canopy configuration, and whether the monitoring target is accessible to that role. Consult the original oss-sec notice and the project's documentation or advisories to confirm the affected version and current guidance; do not assume the translated description is complete.

If you use AI to summarize the notice or prepare an analysis, submit only the material needed and remove credentials, personal identifiers, and sensitive internal details. Rota Nacional's data barrier detects personal data before model execution and applies the organization's policy; it does not fix or assess this BanyanDB vulnerability.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free