An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction. | |
| Title | Unauthenticated Remote Code Execution in Akana API Platform | |
| Weaknesses | CWE-41 CWE-863 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Perforce
Published:
Updated: 2026-09-09T12:33:44.218Z
Reserved: 2026-09-04T18:45:33.859Z
Link: CVE-2026-85978
No data.
Status : Received
Published: 2026-09-09T11:17:16.073
Modified: 2026-09-09T11:17:16.073
Link: CVE-2026-85978
No data.
OpenCVE Enrichment
Updated: 2026-09-09T12:00:08Z