CVE-2026-85978

9.8

Perforce · Akana

A path normalization flaw in Perforce Akana allows unauthenticated remote code execution via the Policy Manager console by bypassing authentication filters and injecting arbitrary script code.

Executive summary

A critical unauthenticated remote code execution vulnerability in the Perforce Akana API Platform allows attackers to achieve full system compromise without requiring user interaction.

Vulnerability

This vulnerability is caused by a path normalization discrepancy between the authentication filter and the servlet dispatcher, which allows an unauthenticated attacker to inject and execute arbitrary code within the Policy Manager console.

Business impact

The vulnerability carries a CVSS score of 9.8, reflecting the highest level of severity due to the lack of required authentication and the potential for total system compromise. A successful exploit could lead to the complete loss of confidentiality, integrity, and availability of the API platform, potentially exposing sensitive API keys, backend configurations, and organizational data.

Remediation

Immediate Action: Upgrade to Perforce Akana version 2024.1.6, 2025.1.2, 2026.2, or later to apply the necessary security patches.

Proactive Monitoring: Review application and server access logs for anomalous request patterns targeting the Policy Manager console, specifically looking for attempts to manipulate URI paths or inject script-like payloads.

Compensating Controls: Deploy a Web Application Firewall (WAF) to block requests containing suspicious path traversal sequences or unauthorized script injection patterns directed at the Akana management interface.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the critical nature of this vulnerability and its potential for full system takeover, immediate patching is required. Organizations should prioritize updating their Akana deployments to the specified fixed versions to eliminate the code injection vector and prevent unauthorized access.

More Perforce CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources