XML External Entity Flaw in Akana API Platform by Perforce
CVE-2026-89212

9.2CRITICAL

Key Information:

Vendor

Perforce

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89212?

A vulnerability exists within the Akana API Platform that allows for XML External Entity (XXE) exploitation due to misconfigured XML-to-JSON processing. This flaw permits attackers to send crafted XML data that gains unauthorized access to internal files or services. The affected Akana versions include 2026.1, 2025.1.1, and all versions prior to 2024.1.6, including unsupported versions. A security patch has been introduced in the latest release to address this serious concern.

Affected Version(s)

Akana Akana API Platform 2024.1.6, 2025.1.2, 2026.2

Akana Akana API Platform All versions prior to 2024.1

Akana Akana API Platform 2024.1.0 <= 2024.1.5

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yoeri Vegt
.