Perforce Akana API Platform Policy Manager Authentication Bypass Leading to Unauthenticated Code Injection (CVE-2026-85978)
Release Date: 9th September 2026
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that operate Perforce Akana, an enterprise API management platform. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-85978 is a critical vulnerability in the Policy Manager console of Perforce Akana, an enterprise API management platform (API gateway, developer portal, and analytics) used by organizations to publish, secure, and manage their APIs. Perforce is a well-established global enterprise software vendor, and Akana is a widely-deployed enterprise-grade API management product.
What are the systems affected?
The following version(s) are affected:
Perforce Akana API Platform (Policy Manager console) – (Affected; specific version range not yet published in third-party reporting)
No fixed version confirmed at time of writing – consult Perforce's own advisory channel for updates.
What does this mean?
Typical attack flow:
- Reach the Policy Manager console with a crafted request — A remote, unauthenticated attacker sends a specially crafted request to the Akana Policy Manager console, exploiting a path normalization discrepancy between the authentication filter and the underlying servlet dispatcher.
- Bypass authentication and inject code for execution — The discrepancy allows the request to bypass the authentication filter entirely and reach an endpoint that processes untrusted script code without protective measures, allowing the attacker to inject and execute arbitrary code on the server.
Attack vectors:
- A network-based, unauthenticated attack against any reachable Perforce Akana Policy Manager console.
- No user interaction or privileges are required.
Successful exploitation may allow attackers to:
- Execute arbitrary code on the server hosting the Akana Policy Manager console, without any authentication.
- Use that code execution to access, modify, or disrupt every API managed through the platform, and potentially pivot into the wider network hosting it.
Mitigation process?
CERTVU recommends the following:
-
Restrict Access to the Policy Manager Console
Restrict network access to the Akana Policy Manager console to trusted administrative networks only, and ensure it is never directly reachable from the internet. -
Monitor for a Patch
Monitor Perforce's advisory channel for a patch. -
Monitor for Unauthorized Activity
Monitor for unauthorized activity on the platform. -
Apply Network Segmentation
Apply network segmentation as defence-in-depth.
Report any suspected compromise of a Perforce Akana deployment to CERTVU at