Pkp-Lib · Pkp-Lib · CVE-2026-19906
**Name of the Vulnerable Software and Affected Versions**
pkp pkp-lib versions 3.3.0 through 3.5.0
**Description**
A weakness exists in the API Key Generation component within the `setData()` function of the `classes/user/form/APIProfileForm.php` file. A remote attacker can manipulate the `apiKey` argument to cause insufficient entropy, which refers to a lack of randomness in the generated keys, potentially making them predictable. This attack is characterized by high complexity and is difficult to exploit.
**Recommendations**
Apply patch 529b5df878e571ccc727647f7748eafc1466b041 for versions 3.3.0 through 3.5.0.