ZeroHour

CVE-2026-89212

moderate

Unauthenticated XXE in Akana API Platform XML-to-JSON Processing

CVSS 4.0
9.2 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-89212 is an XML external entity (XXE) injection flaw (CWE-611) in the Akana API Platform, where external entity references are improperly restricted during XML-to-JSON processing. Because the affected path is reachable over the network without privileges, prior access, or user interaction (CVSS 4.0: AV:N/AC:L/AT:N/PR:N/UI:N), an attacker can submit crafted XML containing external entity references to trigger the flaw. Successful exploitation yields high confidentiality impact on the vulnerable system and high subsequent-system confidentiality impact with low subsequent-system integrity impact (VC:H/SC:H/SI:L), consistent with reading local files or secrets from the platform and reaching internal resources via SSRF. All users of Akana API Platform versions 2026.1, 2025.1.1, and any version before 2024.1.6 — including older unsupported releases — are affected; a fix ships as a security patch in the latest release of each supported version line. There is no evidence of exploitation so far: the flaw is not in CISA KEV and no public proof-of-concept is known.

What to do: Upgrade every Akana deployment to the latest patch release of its supported version line — at least 2024.1.6 if running 2024.1.x or older, and the newest 2025.1.x/2026.1.x patch releases otherwise — since unsupported older releases must be migrated to a supported line to receive the fix. Until patched, restrict or disable external entity resolution in the XML-to-JSON processing path, limit the platform's outbound network access to curb SSRF, and restrict which clients can submit XML payloads. Inventory all Akana gateway and portal instances, prioritizing those with XML endpoints exposed to the internet.

Affected
Akana (Perforce) Akana API Platform2026.1
Akana (Perforce) Akana API Platform2025.1.1
Akana (Perforce) Akana API Platformall versions before 2024.1.6, including older unsupported versions
Estimated exposure
moderate≈1,000–10,000 deployed instances (estimate; no public install-base or scan data available) — Akana API Platform is an enterprise API-management product typically deployed as dedicated gateway/portal instances inside large organizations, which implies a global install base on the order of thousands of instances rather than millions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.

Weakness
CWE-611
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.