Vulnerability  ·  2026-10-12

Katanemo Plano: unauthenticated access to Envoy admin interface exposes LLM provider API keys in plaintext (CVSS 7.5)

VulnerabilityHigh impactGlobalCVE-2026-108863
VulnCheck published CVE-2026-108863 (published 2026-10-11, CVSS 7.5 v3.1 / 8.7 v4.0, CWE-306 missing authentication) for Katanemo Plano < 0.4.37: the Envoy admin interface is enabled without auth and bound to all interfaces, so /config_dump discloses configured LLM provider API keys in plaintext. Verified against NVD REST API.
An AI/LLM gateway (Plano) ships LLM-provider credentials on an unauthenticated, internet-exposed administrative surface. An attacker retrieving those keys gains direct billing abuse of the LLM providers, plus potential access to any upstream service those keys authenticate to — a direct AI-credential exposure with trivial exploitation.
Unauthenticated network attacker requests the Envoy admin /config_dump endpoint on port 9901 (bound to 0.0.0.0 by default) and reads LLM provider API keys stored in plaintext in the WASM filter configuration.
Katanemo Plano through 0.4.37 (pypi: planoai)
Upgrade past 0.4.37 and/or bind the Envoy admin interface to loopback and require authentication; rotate all exposed LLM provider API keys. Advisory: https://www.vulncheck.com/advisories/katanemo-plano-through-0.4.37-missing-authentication-on-envoy-admin-interface
NVD CVE-2026-108863VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →