Skip to content
CVE-2026-108863: Katanemo Plano Authentication Flaw Exposes Secrets

CVE-2026-108863: Katanemo Plano Authentication Flaw Exposes Secrets

First seen 11 Oct 2026, 20:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 21:28 UTC
  • •Katanemo Plano versions up to 0.4.37 are vulnerable to unauthenticated access.
  • •Attackers can exploit the flaw to access sensitive API keys via the /config_dump endpoint.
  • •Immediate mitigation includes upgrading to a fixed version and blocking access to port 9901.

Katanemo Plano versions up to 0.4.37 have a missing authentication vulnerability in the Envoy admin interface, allowing unauthenticated attackers to access sensitive configuration data on port 9901. This vulnerability, identified as CVE-2026-108863, enables attackers to retrieve API keys in plaintext via the /config_dump endpoint. The risk is classified as high due to potential credential misuse, although there is currently no evidence of active exploitation. Affected systems include any internet-accessible deployments where the admin interface is exposed. Mitigation steps include upgrading to a fixed version and blocking access to the vulnerable port. The vulnerability was disclosed on 2026-10-11, with a CVSS score of 8.7 indicating its severity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-10-11
CVE-2026-108863 published
Katanemo Plano vulnerability disclosed, allowing unauthenticated access to sensitive data.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track Envoy and CVE-2026-108863 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions are affected?
Katanemo Plano versions through 0.4.37 are affected by this vulnerability.
Is there evidence of exploitation?
Currently, there is no evidence of active exploitation reported.
What should I do if I'm affected?
Upgrade to a vendor-fixed release and block access to port 9901 until patched.