CVE-2026-85978
9.8Perforce · Akana
A path normalization flaw in Perforce Akana allows unauthenticated remote code execution via the Policy Manager console by bypassing authentication filters and injecting arbitrary script code.
Executive summary
A critical unauthenticated remote code execution vulnerability in the Perforce Akana API Platform allows attackers to achieve full system compromise without requiring user interaction.
Vulnerability
This vulnerability is caused by a path normalization discrepancy between the authentication filter and the servlet dispatcher, which allows an unauthenticated attacker to inject and execute arbitrary code within the Policy Manager console.
Business impact
The vulnerability carries a CVSS score of 9.8, reflecting the highest level of severity due to the lack of required authentication and the potential for total system compromise. A successful exploit could lead to the complete loss of confidentiality, integrity, and availability of the API platform, potentially exposing sensitive API keys, backend configurations, and organizational data.
Remediation
Immediate Action: Upgrade to Perforce Akana version 2024.1.6, 2025.1.2, 2026.2, or later to apply the necessary security patches.
Proactive Monitoring: Review application and server access logs for anomalous request patterns targeting the Policy Manager console, specifically looking for attempts to manipulate URI paths or inject script-like payloads.
Compensating Controls: Deploy a Web Application Firewall (WAF) to block requests containing suspicious path traversal sequences or unauthorized script injection patterns directed at the Akana management interface.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the critical nature of this vulnerability and its potential for full system takeover, immediate patching is required. Organizations should prioritize updating their Akana deployments to the specified fixed versions to eliminate the code injection vector and prevent unauthorized access.
More Perforce CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section