Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-89212: Akana API Platform may expose internal files
CVE-2026-89212 · published 29 days ago
Summary
The Akana API Platform can be fooled by specially crafted XML data to read files or data it should not access. This could let an attacker view sensitive information stored on the server. Apply the latest security patch or upgrade to a supported version as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| perforce | akana | All versions prior to 2024.1 |
Original advisory text
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, ...
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.2
Critical
Type
CWE-611XML External Entity (XXE)
Timeline
Published11 Sep 2026
Updated7 Oct 2026
First seen11 Sep 2026
Track software like this
Free during beta