CVE-2026-89212

Summary

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.

Affected Software

VendorProductVersion RangeStatus
PerforceAkana2024.1.6, 2025.1.2, 2026.2unaffected
PerforceAkanaAll versions prior to 2024.1affected
PerforceAkana2024.1.0 <= 2024.1.5affected
PerforceAkana2025.1.0 <= 2025.1.1affected
PerforceAkana2026.1affected

Weaknesses

  • CWE-611: CWE-611 Improper restriction of XML external entity reference

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References