A flaw resulting in XML external entity (XXE) was found in Akana API Platform
Akana API Platform can expose sensitive information when processing specially crafted XML. A remote attacker needs no account or user interaction.
- Severity
- HighCVSS 3.1 · 8.6 · puppet.com
- Fix
- Fixed in 2024.1.6
- Affected versions
- All versions prior to 2024.1; 2024.1.0 through 2024.1.5; 2025.1.0 through 2025.1.1+1 more
- Weakness
- CWE-611XML External Entity (XXE)
- Affects
- Akana
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: partial
- EU ID
- EUVD-2026-76103ENISA vulnerability database
How it works
- A remote attacker can send specially constructed XML to Akana API Platform.
- During conversion to JSON, the platform fails to block references outside the submitted data.
- The platform can then retrieve information identified by those references, exposing sensitive data.
What to do
If you administer Akana API Platform, compare its installed release with the affected ranges. Check for versions older than 2024.1, 2024.1.0 through 2024.1.5, 2025.1.0 through 2025.1.1, or 2026.1.
Update 2024.1 installations to 2024.1.6 and 2025.1 installations to 2025.1.2. Upgrade 2026.1 installations to 2026.2. Move versions older than 2024.1 to a supported fixed release.
Technical details
CVE-2026-89212 is an XML external entity flaw in Akana API Platform's XML-to-JSON processing. Network attackers need no privileges or user interaction, and successful exploitation can expose confidential information. Affected releases include everything before 2024.1, 2024.1.0 through 2024.1.5, 2025.1.0 through 2025.1.1, and 2026.1. Fixed releases are 2024.1.6, 2025.1.2, and 2026.2.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact None No data tampering
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Open in FIRST.org calculatorReferences
- cvefeed.io · CVE-2026-89212 third party advisory vdb entry
- cve.org · CVERecord vdb entry
- euvd.enisa.europa.eu · EUVD-2026-76103 vdb entry
- cveawg.mitre.org · CVE-2026-89212
- portal.perforce.com · xml-external-entity-in-akana-api-platform NVD