CVE-2026-89212 CRITICAL

CVE-2026-89212: XML External Entity in Akana API Platform

Vendor Perforce
Product Akana
Weakness CWE-611 · XXE
Published September 11, 2026
Last update September 11, 2026

CVSS base score

9.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N

What the vulnerability does

01Description

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.

Key dates

02Disclosure timeline

September 11, 2026 CVE published
September 11, 2026 Record updated

Related vulnerabilities

04Related CVE