
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30778 is an information disclosure vulnerability in Apache SkyWalking's OAP (Observability Analysis Platform) server, where the /debugging/config/dump endpoint may leak sensitive configuration information for MySQL and PostgreSQL databases. It affects Apache SkyWalking versions 9.7.0 through 10.3.0 (Maven package org.apache.skywalking:server-core). The vulnerability was disclosed on April 15, 2026, with a patch released in version 10.4.0. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, OSS-Sec).
The root cause is classified as CWE-202 (Exposure of Sensitive Information Through Data Queries), where the /debugging/config/dump endpoint in SkyWalking OAP exposes internal configuration data without enforcing authentication or access controls. An unauthenticated remote attacker can send a simple HTTP request to this endpoint over the network to retrieve sensitive database configuration details, including credentials and connection strings for MySQL and PostgreSQL backends. No special privileges, user interaction, or complex conditions are required for exploitation. The fix was introduced in commit 5a3f626 of the Apache SkyWalking repository (GitHub Advisory, OSS-Sec).
Successful exploitation allows an unauthenticated network attacker to obtain sensitive database configuration data, potentially including credentials (usernames and passwords) and connection strings for MySQL and PostgreSQL instances used by SkyWalking. This could enable unauthorized access to backend databases, leading to data exfiltration, data manipulation, or further lateral movement within the infrastructure. The impact is limited to confidentiality — there is no direct integrity or availability impact from this vulnerability itself (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017% (0.000170), placing it in the 13th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported.
nmap) targeting the default SkyWalking OAP HTTP port (typically 12800).GET /debugging/config/dump HTTP/1.1 on the target SkyWalking OAP server./debugging/config/dump on the SkyWalking OAP HTTP port (default 12800) from untrusted or external IP addresses./debugging/config/dump from unauthorized sources; repeated or scripted access patterns to this endpoint.The primary remediation is to upgrade Apache SkyWalking to version 10.4.0 or later, which resolves the vulnerability (GitHub Advisory, OSS-Sec). For organizations unable to patch immediately, restrict network access to the /debugging/config/dump endpoint via firewall rules or reverse proxy access controls, limiting it to trusted internal networks or administrative hosts only. Additionally, consider rotating database credentials for MySQL and PostgreSQL instances used by SkyWalking as a precautionary measure if the endpoint was previously exposed.
The vulnerability was reported by shuiboye@gmail.com and disclosed by Apache SkyWalking maintainer Kai Wan via the oss-security mailing list on April 15, 2026 (OSS-Sec). A brief mention was noted on Bluesky (infosec.skyfleet.blue) and Mastodon (thehackerwire) shortly after disclosure, indicating routine community awareness without significant alarm given the absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."