Unauthenticated Remote Code Execution in Akana API Platform
CVE-2026-85978

10CRITICAL

Key Information:

Vendor

Perforce

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-85978?

A security vulnerability in the Policy Manager console of the Akana API Platform allows attackers to exploit a path normalization flaw between the authentication filter and servlet dispatcher. By sending a specially crafted request, an unauthorized user could bypass authentication, reaching sensitive endpoints that execute provided script code without appropriate sandboxing measures. This exploit could lead to arbitrary code execution, presenting a significant risk as it requires no authentication or interaction from the user, making it essential for users of Akana API Platform to address this issue promptly.

Affected Version(s)

Akana Akana API Platform 2024.1.6, 2025.1.2, 2026.2

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.