What is CVE-2026-64859?
CVE-2026-64859 affects the New API LLM gateway and AI asset management system. Before version 1.0.0-rc.7, admin user list APIs incorrectly expose the `access_token` due to improper serialization. Affected users should update to the patched version immediately.
Azərbaycanca: CVE-2026-64859, New API adlı LLM gateway və AI asset management sistemində aşkarlanıb. 1.0.0-rc.7 versiyasından əvvəl admin istifadəçi siyahısı API-ləri səhvən `access_token` dəyərini qaytarır. Təsirlənən versiyaları istifadə edənlər dərhal təhlükəsiz versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which system does CVE-2026-64859 affect?
CVE-2026-64859 affects the New API LLM gateway and AI asset management system.
What is the impact of this vulnerability?
Before version 1.0.0-rc.7, admin user list APIs incorrectly expose the `access_token` value.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.