Missing Authentication Vulnerability in Katanemo Plano by Katanemo
CVE-2026-108863

8.7HIGH

Key Information:

Vendor

Katanemo

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108863?

Katanemo Plano, up to version 0.4.37, has a significant missing authentication issue that allows unauthorized network attackers to access the Envoy admin interface. This interface is erroneously bound to all host interfaces on port 9901. By exploiting this vulnerability, attackers can interact with the /config_dump endpoint, which exposes sensitive LLM provider API keys stored in plaintext within the WASM filter configuration. Timely remediation is essential to protect sensitive configuration data and maintain system integrity.

Affected Version(s)

Plano 0 <= 0.4.37

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.