PT-2026-76690 · Go+3 · Github.Com/Quantumnous/New-Api+2

CVE-2026-64866

·

Published

2026-08-17

·

Updated

2026-09-04

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions New API versions 0.9.1.3 through 1.0.0-rc.6
Description An authorization flaw exists in the AdminResetPasskey function within controller/passkey.go. The endpoint DELETE /api/user/:id/reset passkey fails to implement the canManageTargetRole check, which is used by other privileged account-protection endpoints. This allows a lower-privileged administrator to remove a passkey from accounts with the same or higher privilege levels, including root accounts, thereby weakening the target account's authentication security.
Recommendations Update to version 1.0.0-rc.7. As a temporary workaround, restrict admin access to trusted operators and block the DELETE /api/user/:id/reset passkey endpoint at the reverse proxy or gateway for all users except root operators.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64866
GHSA-P845-629J-RCJ6
GO-2026-6244
OPENSUSE-SU-2026:21761-1

Affected Products

Github.Com/Quantumnous/New-Api
Govulncheck-Vulndb
New Api