PT-2026-76690 · Go+3 · Github.Com/Quantumnous/New-Api+2
CVE-2026-64866
·
Published
2026-08-17
·
Updated
2026-09-04
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
New API versions 0.9.1.3 through 1.0.0-rc.6
Description
An authorization flaw exists in the
AdminResetPasskey function within controller/passkey.go. The endpoint DELETE /api/user/:id/reset passkey fails to implement the canManageTargetRole check, which is used by other privileged account-protection endpoints. This allows a lower-privileged administrator to remove a passkey from accounts with the same or higher privilege levels, including root accounts, thereby weakening the target account's authentication security.Recommendations
Update to version 1.0.0-rc.7.
As a temporary workaround, restrict admin access to trusted operators and block the
DELETE /api/user/:id/reset passkey endpoint at the reverse proxy or gateway for all users except root operators.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github.Com/Quantumnous/New-Api
Govulncheck-Vulndb
New Api