CVE-2026-85978

Summary

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.

Affected Software

VendorProductVersion RangeStatus
PerforceAkana2024.1.6, 2025.1.2, 2026.2unaffected
PerforceAkanaAll versions prior to 2024.1affected
PerforceAkana2024.1.0 <= 2024.1.5affected
PerforceAkana2025.1.0 <= 2025.1.1affected
PerforceAkana2026.1affected

Weaknesses

  • CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
  • CWE-41: CWE-41 Improper resolution of path equivalence
  • CWE-863: CWE-863: Incorrect Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References