ZeroHour

CVE-2026-85978

niche

Unauthenticated RCE in Akana API Platform Policy Manager console

CVSS 4.0
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-85978 is an unauthenticated remote code execution flaw in the Policy Manager console of the Akana API Platform. A path normalization discrepancy between the console's authentication filter and its servlet dispatcher lets a crafted request bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing. A remote, unauthenticated attacker can therefore execute arbitrary code on the server hosting the console, with no user interaction required. Any deployment exposing the Akana API Platform Policy Manager console is affected. As of the current data, the flaw is not listed in CISA's KEV, no public proof-of-concept is known, and there are no confirmed reports of in-the-wild exploitation.

What to do: Upgrade Akana API Platform to the patched release identified in the vendor security advisory, since no specific fixed version numbers are provided in this data. Until patched, restrict network access to the Policy Manager console (allow only trusted management networks or place it behind a VPN/WAF) and review access logs for unauthenticated requests that reach Policy Manager endpoints, particularly those containing path traversal or normalization variants. Confirm that any internet-exposed console instances are prioritized for patching.

Affected
Akana (Perforce) Akana API Platform - Policy Manager console
Estimated exposure
nichelikely on the order of hundreds to a few thousand enterprise deployments; precisely unknown — Akana API Platform is a specialized enterprise API management product with no public install-base or internet-scan counts in the available data, so this order-of-magnitude estimate reflects its niche, per-organization deployment pattern…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.

Weakness
CWE-41, CWE-94, CWE-863
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.