Impact
The Akana API Platform Policy Manager console contains a security flaw that lets an unauthenticated request bypass the authentication filter by exploiting a path normalization mismatch. The crafted request reaches an endpoint that evaluates attacker‑supplied script code in an unsandboxed environment, enabling the attacker to execute arbitrary code on the host. This permissive code execution can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw affects the Akana API Platform, specifically the Policy Manager console component from Perforce:Akana. The CVE does not specify vulnerable versions, so all installations of the policy manager console are potentially impacted until a patch is applied. Any deployment that exposes the console to the internet or an untrusted network is at risk.
Risk and Exploitability
The CVSS score of 10 reflects the severity of the flaw, and the absence of EPSS data suggests no publicly available exploit but does not reduce its risk. Because the vulnerability requires no authentication or user interaction, the attacker does not need any prior user credentials; this lack of required privileges allows the flaw to be targeted from any network segment that can reach the console endpoint. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS score warrants immediate attention from security teams.
OpenCVE Enrichment