{"id":"CVE-2026-108863","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-108863","summary":"Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all…","details":"Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces on port 9901. Attackers can request the /config_dump endpoint to read configured LLM provider API keys in plaintext from the WASM filter configuration.","published":"2026-10-11T14:17:06.360","modified":"2026-10-11T14:17:06.360","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/katanemo/plano"},{"type":"WEB","url":"https://github.com/katanemo/plano/blob/0.4.37/cli/planoai/config_generator.py#L588-L656"},{"type":"WEB","url":"https://github.com/katanemo/plano/blob/0.4.37/config/envoy.template.yaml#L1-L3"},{"type":"WEB","url":"https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/katanemo-plano-envoy-admin-config-secret-disclosure"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/katanemo-plano-through-0.4.37-missing-authentication-on-envoy-admin-interface"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-11T14:17:06.360"}}