VYPR

API Platform

by Akamai

CVEs (6)

  • CVE-2026-85978CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an…

  • CVE-2024-2796CriApr 18, 2024
    risk 0.60cvss 9.3epss 0.00

    A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.

  • CVE-2026-89212HigSep 11, 2026
    risk 0.56cvss 8.6epss 0.00

    A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions…

  • CVE-2024-3930MedJul 30, 2024
    risk 0.41cvss 6.3epss 0.00

    In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

  • CVE-2024-5249MedJul 30, 2024
    risk 0.35cvss 5.4epss 0.00

    In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.

  • CVE-2024-5250LowJul 30, 2024
    risk 0.23cvss 3.5epss 0.00

    In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations