# CVE-2026-85978

## Summary

- **CVE ID:** CVE-2026-85978
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-94, CWE-41, CWE-863
- **Published:** Sep 9, 2026
- **Last Modified:** Sep 9, 2026

## Description

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.

## Affected Products

- Perforce — Akana (2024.1.6, 2025.1.2, 2026.2)
- Perforce — Akana (2024.1.0)
- Perforce — Akana (2025.1.0)
- Perforce — Akana (2026.1.0)
- Perforce — Akana (All versions prior to 2024.1)
- Perforce — Akana (2026.1)

## References

- [CNA](https://portal.perforce.com/s/cve/a91Qi000003CcxRIAS/unauthenticated-remote-code-execution-in-akana-policy-manager-console)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._