Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-30778

26
FAUCET Score

CVE-2026-30778 is an information disclosure vulnerability in Apache SkyWalking affecting versions 9.7.0 through 10.3.0, wherein the /debugging/config/dump endpoint may leak sensitive database configuration details for MySQL and PostgreSQL deployments. This exposure of credentials and connection parameters could enable attackers to establish unauthorized database access or facilitate lateral movement within affected environments. The vulnerability carries a CVSS 7.5 HIGH severity rating due to its network-accessible attack vector that requires no authentication or user interaction, though it is limited to information disclosure without direct confidentiality impact to data integrity or availability. The relatively high attack surface combined with zero authentication requirements presents significant risk to organizations operating vulnerable SkyWalking versions. Current exploitation status indicates this vulnerability has not yet been formally assigned to the Known Exploited Vulnerabilities catalog, nor is it listed on active threat intelligence platforms. The EPSS score of 0.00037 suggests minimal real-world exploitation activity to date. Apache has issued a patch in version 10.4.0, and organizations should prioritize upgrading affected SkyWalking deployments to remediate this exposure, particularly those with internet-facing monitoring infrastructure.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.7.0, < 10.4.0CPE matchmatch criteria
cpe:2.3:a:apache:skywalking:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 20th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

mavenpatch availablevia ghsa
Product: org.apache.skywalking:server-coreFixed in: 10.4.0
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

mavenGHSA-27h3-crw2-q36whigh

SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information

Apr 16, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10934.html

CVE-2026-30778: Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.

Apr 15, 2026

References

openwall.com / lists/oss-security/2026/04/15/2
Mailing ListThird Party Advisory
lists.apache.org / thread/pvf35o3tp1rqhmrhzj6fg31gvqrqcvn3
Mailing ListVendor Advisory