{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akatanemoplano/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:katanemo:plano:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108863"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Plano (\u003c= 0.4.37)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","exposure","envoy","credential-theft"],"_cs_type":"advisory","_cs_vendors":["Katanemo"],"content_html":"\u003cp\u003eKatanemo Plano versions 0.4.37 and earlier contain a critical missing authentication vulnerability in its Envoy proxy deployment. The Envoy admin interface, which is typically used for diagnostic and configuration tasks, is improperly exposed and bound to all host interfaces on TCP port 9901. This configuration flaw allows any unauthenticated network attacker with connectivity to the interface to query the /config_dump endpoint. This endpoint returns the full proxy configuration in JSON format. Because Katanemo Plano stores LLM provider API keys as plaintext values within the WASM filter configuration, successful exploitation results in the immediate exfiltration of sensitive credentials used to interface with external Large Language Model services. This vulnerability poses a significant risk to organizations relying on Plano for LLM gateway orchestration, as the exposure of these keys could lead to unauthorized cost accumulation or data leakage via downstream service providers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to steal sensitive API credentials required to access and utilize external LLM providers. This effectively grants the attacker the ability to spoof the organization's identity when interacting with these services, leading to potential unauthorized charges or access to sensitive model interactions. The vulnerability impacts all deployments of Plano version 0.4.37 and older where the Envoy admin port 9901 is reachable via the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to TCP port 9901 immediately via host-based firewalls or network access control lists (NACLs) to ensure only authorized management workstations can access the Envoy admin interface.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for inbound connections directed at TCP port 9901 from untrusted sources or internal segments not designated for administration.\u003c/li\u003e\n\u003cli\u003eRotate all LLM provider API keys configured within the Plano environment, as they must be assumed compromised if the instance has been exposed to an untrusted network.\u003c/li\u003e\n\u003cli\u003eUpgrade all instances of Katanemo Plano to a patched version beyond 0.4.37 once released by the vendor.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T16:02:59Z","date_published":"2026-10-11T16:02:59Z","id":"https://feed.craftedsignal.io/briefs/2026-10-katanemo-plano-auth/","summary":"Katanemo Plano versions 0.4.37 and earlier contain a missing authentication vulnerability on the Envoy admin interface that allows unauthenticated remote attackers to exfiltrate LLM provider API keys.","title":"Unauthenticated Exposure of Envoy Admin Interface in Katanemo Plano","url":"https://feed.craftedsignal.io/briefs/2026-10-katanemo-plano-auth/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:katanemo:plano:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}