CVE-2026-108863
Received Received - Intake

Authentication Bypass in Katanemo Plano Exposes API Keys

Vulnerability report for CVE-2026-108863, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces on port 9901. Attackers can request the /config_dump endpoint to read configured LLM provider API keys in plaintext from the WASM filter configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Katanemo Plano 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Katanemo Plano through version 0.4.37 has a missing authentication vulnerability. This flaw allows unauthenticated attackers on the network to access the Envoy admin interface, which is exposed on all host interfaces via port 9901. Attackers can exploit this by requesting the /config_dump endpoint to retrieve configured LLM provider API keys in plaintext from the WASM filter configuration.

Detection Guidance

Check if the Envoy admin interface is exposed on port 9901 by running: netstat -tulnp | grep 9901 or ss -tulnp | grep 9901. If accessible, test for unauthenticated access by sending a request to http://<target-ip>:9901/config_dump. If the response contains plaintext LLM provider API keys, the system is vulnerable.

Impact Analysis

This vulnerability allows attackers to steal sensitive API keys used by the LLM provider, potentially leading to unauthorized access to services, data breaches, or further exploitation of connected systems. The exposure of these keys could enable attackers to impersonate legitimate services or intercept communications.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive data and API keys. GDPR requires protection of personal data, while HIPAA mandates safeguarding protected health information. A breach could result in legal penalties, fines, and reputational damage.

Mitigation Strategies

Immediately restrict access to the Envoy admin interface by binding it to localhost only or configuring a firewall rule to block external access to port 9901. Update Katanemo Plano to the latest version that patches this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108863. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart