Critical severityNVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-85978
CVE-2026-85978
Description
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.