What is CVE-2026-64866?
The CVE-2026-64866 vulnerability was found in New API LLM gateway. Due to a missing canManageTargetRole authorization check in AdminResetPasskey, a lower-privileged admin can reset other users' passkeys via DELETE request. Versions 0.9.1.3 to 1.0.0-rc.7 are affected, and immediate update is required.
Azərbaycanca: CVE-2026-64866 zəifliyi New API LLM şlüuzunda aşkarlanıb. AdminResetPasskey funksiyasında canManageTargetRole icazə yoxlamasının olmaması səbəbilə aşağı səlahiyyətli admin DELETE sorğusu ilə digər istifadəçilərin parol açarını sıfırlaya bilər. 0.9.1.3-dən 1.0.0-rc.7-dək versiyalar təsirlənir və dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What is the cause of the CVE-2026-64866 vulnerability?
A missing canManageTargetRole authorization check in the AdminResetPasskey function.
Which versions of the New API LLM gateway are affected by CVE-2026-64866?
Versions from 0.9.1.3 to 1.0.0-rc.7 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.