CVE-2026-85978: Perforce Akana
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.
Affected products
- Perforce Akana: before 2024.1 (fixed in 2024.1); from 2024.1.0, up to and including 2024.1.5; from 2025.1.0, up to and including 2025.1.1; version 2026.1 only
Published 2026-09-09. Last modified 2026-09-09.