PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108863 Katanemo CVE debrief

CVE-2026-108863 is a high-severity vulnerability in Katanemo Plano through version 0.4.37, allowing unauthenticated network attackers to access the Envoy admin interface on port 9901. Attackers can exploit this vulnerability to read configured LLM provider API keys in plaintext from the WASM filter configuration by requesting the /config_dump endpoint.

Vendor
Katanemo
Product
Plano
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for securing Katanemo Plano deployments should assess exposure to this vulnerability and prioritize securing access to the Envoy admin interface to prevent unauthorized API key disclosure.

Why it matters

CVE-2026-108863 is a high-severity vulnerability in Katanemo Plano that allows unauthenticated network attackers to access the Envoy admin interface and read configured LLM provider API keys in plaintext. Defenders should prioritize verifying exposure, securing access, and monitoring for unauthorized API key disclosure.

  • Verify exposure of the Envoy admin interface on port 9901
  • Restrict access to the Envoy admin interface to prevent unauthorized access
  • Monitor for unauthorized API key disclosure to detect potential exploitation
  • Update to a version of Katanemo Plano that addresses this vulnerability to prevent future exploitation

Technical summary

The vulnerability exists in Katanemo Plano through version 0.4.37, where the Envoy admin interface is bound to all host interfaces on port 9901 without authentication. This allows unauthenticated network attackers to access the interface and read configured LLM provider API keys in plaintext from the WASM filter configuration by requesting the /config_dump endpoint. Defenders should prioritize verifying exposure of the Envoy admin interface and securing access to prevent unauthorized API key disclosure. Affected product deployments should be identified and owners assigned for follow-up. Official advisories and CVE records should be reviewed to validate affected scope, severity, and vendor guidance.

Defensive priority

Defenders should prioritize verifying exposure of the Envoy admin interface and securing access to prevent unauthorized API key disclosure.

Recommended defensive actions

  • Verify exposure of the Envoy admin interface on port 9901
  • Restrict access to the Envoy admin interface
  • Monitor for unauthorized API key disclosure
  • Update to a version of Katanemo Plano that addresses this vulnerability
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. However, there is limited information on exploitation, impact, or remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108863 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108863

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108863 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108863

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Katanemo Plano through 0.4.37 Missing Authentication on Envoy Admin Interface

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108863.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/katanemo-plano-envoy-admin-config-secret-disclosure

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/katanemo/plano/blob/0.4.37/config/envoy.template.yaml

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/katanemo/plano/blob/0.4.37/cli/planoai/config_generator.py

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/katanemo/plano

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/katanemo-plano-through-0.4.37-missing-authentication-on-envoy-admin-interface

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.