CVE-2026-108863
Description
Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces on port 9901. Attackers can request the /config_dump endpoint to read configured LLM provider API keys in plaintext from the WASM filter configuration.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/katanemo/plano
- https://github.com/katanemo/plano/blob/0.4.37/cli/planoai/config_generator.py#L588-L656
- https://github.com/katanemo/plano/blob/0.4.37/config/envoy.template.yaml#L1-L3
- https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/katanemo-plano-envoy-admin-config-secret-disclosure
- https://www.vulncheck.com/advisories/katanemo-plano-through-0.4.37-missing-authentication-on-envoy-admin-interface
CWEs
CWE-306
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.