CVE-2026-30778 is an information disclosure vulnerability in Apache SkyWalking affecting versions 9.7.0 through 10.3.0, wherein the /debugging/config/dump endpoint may leak sensitive database configuration details for MySQL and PostgreSQL deployments. This exposure of credentials and connection parameters could enable attackers to establish unauthorized database access or facilitate lateral movement within affected environments. The vulnerability carries a CVSS 7.5 HIGH severity rating due to its network-accessible attack vector that requires no authentication or user interaction, though it is limited to information disclosure without direct confidentiality impact to data integrity or availability. The relatively high attack surface combined with zero authentication requirements presents significant risk to organizations operating vulnerable SkyWalking versions. Current exploitation status indicates this vulnerability has not yet been formally assigned to the Known Exploited Vulnerabilities catalog, nor is it listed on active threat intelligence platforms. The EPSS score of 0.00037 suggests minimal real-world exploitation activity to date. Apache has issued a patch in version 10.4.0, and organizations should prioritize upgrading affected SkyWalking deployments to remediate this exposure, particularly those with internet-facing monitoring infrastructure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.7.0, < 10.4.0CPE matchmatch criteria | cpe:2.3:a:apache:skywalking:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information
Apr 16, 2026CVE-2026-30778: Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
Apr 15, 2026