What happened
VulnCheck published CVE-2026-108863 (published 2026-10-11, CVSS 7.5 v3.1 / 8.7 v4.0, CWE-306 missing authentication) for Katanemo Plano < 0.4.37: the Envoy admin interface is enabled without auth and bound to all interfaces, so /config_dump discloses configured LLM provider API keys in plaintext. Verified against NVD REST API.
Why it matters
An AI/LLM gateway (Plano) ships LLM-provider credentials on an unauthenticated, internet-exposed administrative surface. An attacker retrieving those keys gains direct billing abuse of the LLM providers, plus potential access to any upstream service those keys authenticate to — a direct AI-credential exposure with trivial exploitation.
Attack vector
Unauthenticated network attacker requests the Envoy admin /config_dump endpoint on port 9901 (bound to 0.0.0.0 by default) and reads LLM provider API keys stored in plaintext in the WASM filter configuration.
Affected systems
Katanemo Plano through 0.4.37 (pypi: planoai)
Mitigation
Upgrade past 0.4.37 and/or bind the Envoy admin interface to loopback and require authentication; rotate all exposed LLM provider API keys. Advisory: https://www.vulncheck.com/advisories/katanemo-plano-through-0.4.37-missing-authentication-on-envoy-admin-interface