Executive brief
Akana API Platform is an enterprise API management solution used to build, deploy, and manage application programming interfaces. A vulnerability in its XML processing allows attackers to read sensitive files and potentially disrupt service by injecting malicious XML entities during API request processing.
Technical details
An XML external entity (XXE) injection vulnerability exists in Akana API Platform's XML-to-JSON conversion functionality due to improper restriction of external entity references. The vulnerability is triggered when the platform processes XML input from network requests without proper validation of entity definitions. An attacker can exploit this to read arbitrary files from the server filesystem, perform server-side request forgery (SSRF) attacks, or cause denial of service. The flaw affects versions 2026.1, 2025.1.1, and all versions before 2024.1.6; patches are available for currently supported versions.
Affected products
- Perforce Akana API Platform 2026.1, 2025.1.1, and all versions before 2024.1.6
Timeline
- 2026-09-11: disclosed
- 2026-09-11: advisory