VYPR
Vendor

Akamai

Products
23
CVEs
27
Across products
36
Status
Private

Products

23

Recent CVEs

27
View all 27 CVEs →
  • CVE-2026-85978CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an…

  • CVE-2019-18847CriAug 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.

  • CVE-2019-11011CriJun 21, 2019
    risk 0.64cvss 9.8epss 0.03

    Akamai CloudTest before 58.30 allows remote code execution.

  • CVE-2016-10157CriJan 23, 2017
    risk 0.64cvss 9.8epss 0.02

    Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code…

  • CVE-2024-7029HigAug 2, 2024
    risk 0.60cvss 8.8epss 0.39

    Commands can be injected over the network and executed without authentication.

  • CVE-2024-2796CriApr 18, 2024
    risk 0.60cvss 9.3epss 0.00

    A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.

  • CVE-2026-89212HigSep 11, 2026
    risk 0.56cvss 8.6epss 0.00

    A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions…

  • CVE-2024-3826HigJul 2, 2024
    risk 0.56cvss —epss 0.00

    In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.

  • CVE-2025-24527HigJan 29, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.

  • CVE-2025-53841HigDec 3, 2025
    risk 0.51cvss 7.8epss 0.00

    The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a…

  • CVE-2021-40683HigOct 4, 2021
    risk 0.51cvss 7.8epss 0.00

    In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.

  • CVE-2026-34354HigMay 8, 2026
    risk 0.48cvss 7.4epss 0.00

    Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU…

  • CVE-2024-45164HigNov 4, 2024
    risk 0.46cvss 7.1epss 0.00

    Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert…

  • CVE-2024-3930MedJul 30, 2024
    risk 0.41cvss 6.3epss 0.00

    In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

  • CVE-2025-52491MedJun 30, 2025
    risk 0.38cvss 5.8epss 0.00

    Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

  • CVE-2025-49493MedJun 30, 2025
    risk 0.38cvss 5.8epss 0.02

    Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

  • CVE-2025-30143MedMar 17, 2025
    risk 0.35cvss 5.4epss 0.00

    Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.

  • CVE-2024-5249MedJul 30, 2024
    risk 0.35cvss 5.4epss 0.00

    In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.

  • CVE-2025-66373MedDec 4, 2025
    risk 0.31cvss 4.8epss 0.00

    Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that includes a chunk size different from the actual size of the following chunk…

  • CVE-2026-26365MedFeb 23, 2026
    risk 0.26cvss 4.0epss 0.00

    Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the…