CVE-2026-89212: XML External Entity in Akana API Platform
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.
Affected Software
Event History
Frequently Asked Questions
Which deployments need remediation?
Akana API Platform versions 2026.1, 2025.1.1, and all versions before 2024.1.6 are affected, including unsupported older releases. The issue is fixed through a security patch in the latest release of supported versions.
What processing path is affected?
The flaw occurs during XML-to-JSON processing, where XML external entity references were not properly restricted.
What level of attacker access is indicated by the severity vector?
The supplied vector indicates network-reachable exploitation with low complexity, no required privileges, and no user interaction. Successful exploitation can have high confidentiality impact and may affect components beyond the initially vulnerable scope.