Akamai
Products
21- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-18847 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2020 | Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1. | ||
| CVE-2019-11011 | Cri | 0.64 | 9.8 | 0.03 | Jun 21, 2019 | Akamai CloudTest before 58.30 allows remote code execution. | ||
| CVE-2016-10157 | Cri | 0.64 | 9.8 | 0.02 | Jan 23, 2017 | Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code… | ||
| CVE-2024-7029 | Hig | 0.60 | 8.8 | 0.39 | Aug 2, 2024 | Commands can be injected over the network and executed without authentication. | ||
| CVE-2024-2796 | Cri | 0.60 | 9.3 | 0.00 | Apr 18, 2024 | A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson. | ||
| CVE-2024-3826 | Hig | 0.56 | — | 0.00 | Jul 2, 2024 | In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality. | ||
| CVE-2025-24527 | Hig | 0.52 | 8.0 | 0.00 | Jan 29, 2025 | An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector. | ||
| CVE-2025-53841 | Hig | 0.51 | 7.8 | 0.00 | Dec 3, 2025 | The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a… | ||
| CVE-2021-40683 | Hig | 0.51 | 7.8 | 0.00 | Oct 4, 2021 | In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution. | ||
| CVE-2026-34354 | Hig | 0.48 | 7.4 | 0.00 | May 8, 2026 | Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU… | ||
| CVE-2024-45164 | Hig | 0.46 | 7.1 | 0.00 | Nov 4, 2024 | Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert… | ||
| CVE-2024-3930 | Med | 0.41 | 6.3 | 0.00 | Jul 30, 2024 | In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered. | ||
| CVE-2025-52491 | Med | 0.38 | 5.8 | 0.00 | Jun 30, 2025 | Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF. | ||
| CVE-2025-49493 | Med | 0.38 | 5.8 | 0.03 | Jun 30, 2025 | Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection. | ||
| CVE-2025-30143 | Med | 0.35 | 5.4 | 0.00 | Mar 17, 2025 | Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties. | ||
| CVE-2024-5249 | Med | 0.35 | 5.4 | 0.00 | Jul 30, 2024 | In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed. | ||
| CVE-2025-66373 | Med | 0.31 | 4.8 | 0.00 | Dec 4, 2025 | Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that includes a chunk size different from the actual size of the following chunk… | ||
| CVE-2026-26365 | Med | 0.26 | 4.0 | 0.00 | Feb 23, 2026 | Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the… | ||
| CVE-2025-54142 | Med | 0.26 | 4.0 | 0.00 | Aug 29, 2025 | Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain… | ||
| CVE-2025-32094 | Med | 0.26 | 4.0 | 0.01 | Aug 7, 2025 | An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" header, and using obsolete line folding, can lead to a discrepancy in how two… |
- risk 0.64cvss 9.8epss 0.02
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
- risk 0.64cvss 9.8epss 0.03
Akamai CloudTest before 58.30 allows remote code execution.
- risk 0.64cvss 9.8epss 0.02
Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code…
- risk 0.60cvss 8.8epss 0.39
Commands can be injected over the network and executed without authentication.
- risk 0.60cvss 9.3epss 0.00
A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.
- risk 0.56cvss —epss 0.00
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.
- risk 0.52cvss 8.0epss 0.00
An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.
- risk 0.51cvss 7.8epss 0.00
The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a…
- risk 0.51cvss 7.8epss 0.00
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
- risk 0.48cvss 7.4epss 0.00
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU…
- risk 0.46cvss 7.1epss 0.00
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert…
- risk 0.41cvss 6.3epss 0.00
In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.
- risk 0.38cvss 5.8epss 0.00
Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.
- risk 0.38cvss 5.8epss 0.03
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
- risk 0.35cvss 5.4epss 0.00
Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.
- risk 0.35cvss 5.4epss 0.00
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
- risk 0.31cvss 4.8epss 0.00
Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that includes a chunk size different from the actual size of the following chunk…
- risk 0.26cvss 4.0epss 0.00
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the…
- risk 0.26cvss 4.0epss 0.00
Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain…
- risk 0.26cvss 4.0epss 0.01
An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" header, and using obsolete line folding, can lead to a discrepancy in how two…