PT-2026-73047 · Pkp-Lib · Pkp-Lib

·

CVE-2026-19906

·

Published

2026-08-15

·

Updated

2026-08-17

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions pkp pkp-lib versions 3.3.0 through 3.5.0
Description A weakness exists in the API Key Generation component within the setData() function of the classes/user/form/APIProfileForm.php file. A remote attacker can manipulate the apiKey argument to cause insufficient entropy, which refers to a lack of randomness in the generated keys, potentially making them predictable. This attack is characterized by high complexity and is difficult to exploit.
Recommendations Apply patch 529b5df878e571ccc727647f7748eafc1466b041 for versions 3.3.0 through 3.5.0.

Exploit

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19906

Affected Products

Pkp-Lib