What is CVE-2026-19906?
CVE-2026-19906 is a vulnerability in pkp-lib's API key generation component, involving insufficient entropy in the setData function of APIProfileForm.php. This affects the manipulation of the apiKey argument. Users should apply patches or follow developer guidance to mitigate the risk.
Azərbaycanca: CVE-2026-19906, pkp-lib kitabxanasının API açar generasiyası komponentində kifayət qədər entropiya olmaması zəifliyidir. Bu, `APIProfileForm.php` faylındakı `setData` funksiyasına təsir edir. İstifadəçilər patç tətbiq etməli və ya proqram tərtibatçısının təlimatlarını izləməlidir.
FAQ2
Which function and file does CVE-2026-19906 affect?
This vulnerability affects the setData function in the APIProfileForm.php file.
What should users do to mitigate this vulnerability?
Users should apply patches or follow the developer's guidance.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.