Missing Authentication Vulnerability in Katanemo Plano by Katanemo
CVE-2026-108863
8.7HIGH
What is CVE-2026-108863?
Katanemo Plano, up to version 0.4.37, has a significant missing authentication issue that allows unauthorized network attackers to access the Envoy admin interface. This interface is erroneously bound to all host interfaces on port 9901. By exploiting this vulnerability, attackers can interact with the /config_dump endpoint, which exposes sensitive LLM provider API keys stored in plaintext within the WASM filter configuration. Timely remediation is essential to protect sensitive configuration data and maintain system integrity.
Affected Version(s)
Plano 0 <= 0.4.37
