A flaw resulting in XML external entity (XXE) was found in Akana API Platform

Published September 11, 2026 CVE-2026-89212

Akana API Platform can expose sensitive information when processing specially crafted XML. A remote attacker needs no account or user interaction.

Severity
HighCVSS 3.1 · 8.6 · puppet.com
Fix
Fixed in 2024.1.6
Affected versions
All versions prior to 2024.1; 2024.1.0 through 2024.1.5; 2025.1.0 through 2025.1.1+1 more
Weakness
CWE-611XML External Entity (XXE)
Affects
Akana
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: yes · Technical impact: partial
EU ID
EUVD-2026-76103ENISA vulnerability database

How it works

  • A remote attacker can send specially constructed XML to Akana API Platform.
  • During conversion to JSON, the platform fails to block references outside the submitted data.
  • The platform can then retrieve information identified by those references, exposing sensitive data.

What to do

If you administer Akana API Platform, compare its installed release with the affected ranges. Check for versions older than 2024.1, 2024.1.0 through 2024.1.5, 2025.1.0 through 2025.1.1, or 2026.1.

Update 2024.1 installations to 2024.1.6 and 2025.1 installations to 2025.1.2. Upgrade 2026.1 installations to 2026.2. Move versions older than 2024.1 to a supported fixed release.

Technical details

CVE-2026-89212 is an XML external entity flaw in Akana API Platform's XML-to-JSON processing. Network attackers need no privileges or user interaction, and successful exploitation can expose confidential information. Affected releases include everything before 2024.1, 2024.1.0 through 2024.1.5, 2025.1.0 through 2025.1.1, and 2026.1. Fixed releases are 2024.1.6, 2025.1.2, and 2026.2.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact None No data tampering
  • Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Open in FIRST.org calculator