CVE-2026-85978 An unauthenticated remote code execution vulnerability… — CVE Notify — TG.ME

🚨 CVE-2026-85978
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.

🎖@cveNotify
September 9, 2026 43