CVE-2026-85978
nicheUnauthenticated RCE in Akana API Platform Policy Manager console
CVE-2026-85978 is an unauthenticated remote code execution flaw in the Policy Manager console of the Akana API Platform. A path normalization discrepancy between the console's authentication filter and its servlet dispatcher lets a crafted request bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing. A remote, unauthenticated attacker can therefore execute arbitrary code on the server hosting the console, with no user interaction required. Any deployment exposing the Akana API Platform Policy Manager console is affected. As of the current data, the flaw is not listed in CISA's KEV, no public proof-of-concept is known, and there are no confirmed reports of in-the-wild exploitation.
What to do: Upgrade Akana API Platform to the patched release identified in the vendor security advisory, since no specific fixed version numbers are provided in this data. Until patched, restrict network access to the Policy Manager console (allow only trusted management networks or place it behind a VPN/WAF) and review access logs for unauthenticated requests that reach Policy Manager endpoints, particularly those containing path traversal or normalization variants. Confirm that any internet-exposed console instances are prioritized for patching.
| Akana (Perforce) Akana API Platform - Policy Manager console | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.
- Weakness
- CWE-41, CWE-94, CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.