Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-89212: Akana API Platform may expose internal files

CVE-2026-89212 · published 29 days ago
Summary

The Akana API Platform can be fooled by specially crafted XML data to read files or data it should not access. This could let an attacker view sensitive information stored on the server. Apply the latest security patch or upgrade to a supported version as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
perforce akana All versions prior to 2024.1
Original advisory text
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, ...
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-611XML External Entity (XXE)
Timeline
Published11 Sep 2026
Updated7 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-89212 · MITRE
Track software like this
Free during beta