VYPR

Plano

by Katanemo

CVEs (1)

  • CVE-2026-108863HigOct 11, 2026
    risk 0.49cvss 7.5epss —

    Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces on port 9901. Attackers can request the /config_dump endpoint to read configured…