Impact
The flaw allows an attacker to inject or access XML external entities when Akana API Platform performs XML to JSON conversion. Because the system does not properly restrict references, the vulnerability can expose internal files or resources, leading to unauthorized data disclosure. The weakness is classified as CWE-611 and does not include denial‑of‑service in the provided description.
Affected Systems
The affected product is Perforce Akana API Platform. Versions 2026.1, 2025.1.1, and all releases prior to 2024.1.6, including unsupported older releases, are affected. A security patch that fixes the flaw has been released for supported versions.
Risk and Exploitability
The vulnerability has a CVSS score of 9.2, indicating high severity. No EPSS data is available and the CVE is not listed in the CISA KEV catalog. The likely attack vector involves sending a crafted XML payload to an endpoint that processes XML input, exploiting the unchecked external entity references. While no publicly documented exploit code is referenced, the nature of the XXE flaw suggests that such an attack could be feasible if the endpoint is accessible.
OpenCVE Enrichment