CVE-2024-3826: Akana

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.

Affected products

  • Akana Akana: from 2022.1.1, before 2022.1.1 (Patch) (fixed in 2022.1.1 (Patch)); from 2022.1.2, before 2022.1.2 (Patch) (fixed in 2022.1.2 (Patch)); from 2022.1.3, before 2022.1.3 (Patch) (fixed in 2022.1.3 (Patch)); from 0.0.0, before 2024.1.0 (fixed in 2024.1.0)
  • Akana Akana API Platform: from 2022.1.1, before 2022.1.1 (CVE-2024-3826 Patch) (fixed in 2022.1.1 (CVE-2024-3826 Patch)); from 2022.1.2, before 2022.1.2 (CVE-2024-3826 Patch) (fixed in 2022.1.2 (CVE-2024-3826 Patch)); from 2022.1.3, before 2022.1.3 (CVE-2024-3826 Patch) (fixed in 2022.1.3 (CVE-2024-3826 Patch)); from 0.0.0, before 2024.1.0 (fixed in 2024.1.0)

Published 2024-07-02. Last modified 2026-06-17.