CVE-2026-108863: Katanemo Plano Authentication Flaw Exposes Secrets
Article Content
- •Katanemo Plano versions up to 0.4.37 are vulnerable to unauthenticated access.
- •Attackers can exploit the flaw to access sensitive API keys via the /config_dump endpoint.
- •Immediate mitigation includes upgrading to a fixed version and blocking access to port 9901.
Katanemo Plano versions up to 0.4.37 have a missing authentication vulnerability in the Envoy admin interface, allowing unauthenticated attackers to access sensitive configuration data on port 9901. This vulnerability, identified as CVE-2026-108863, enables attackers to retrieve API keys in plaintext via the /config_dump endpoint. The risk is classified as high due to potential credential misuse, although there is currently no evidence of active exploitation. Affected systems include any internet-accessible deployments where the admin interface is exposed. Mitigation steps include upgrading to a fixed version and blocking access to the vulnerable port. The vulnerability was disclosed on 2026-10-11, with a CVSS score of 8.7 indicating its severity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Envoy and CVE-2026-108863 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions are affected?
Is there evidence of exploitation?
What should I do if I'm affected?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…