CVE-2026-89212
XML External Entity in Akana API Platform
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.
| CWE | CWE-611 |
| Vendor | perforce |
| Product | akana |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for perforce akana
Be the first to know when new high vulnerabilities affecting perforce akana are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Perforce / Akana
All versions prior to 2024.1 2024.1.0 โค 2024.1.5 2025.1.0 โค 2025.1.1 2026.1
References
Credits
Yoeri Vegt