Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction. | |
| Title | Unauthenticated Remote Code Execution in Akana API Platform | |
| Weaknesses | CWE-41 CWE-863 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Perforce
Published:
Updated: 2026-09-09T10:34:10.519Z
Reserved: 2026-09-04T18:45:33.859Z
Link: CVE-2026-85978
No data.
Status : Received
Published: 2026-09-09T11:17:16.073
Modified: 2026-09-09T11:17:16.073
Link: CVE-2026-85978
No data.
OpenCVE Enrichment
No data.
