Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p845-629j-rcj6 | New API: Admin can reset passkeys for same-level or higher-privileged users |
Mon, 17 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumnous
Quantumnous new-api |
|
| Vendors & Products |
Quantumnous
Quantumnous new-api |
Mon, 17 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a lower-privileged administrator to remove a passkey from a same-level or higher-privileged account, including a root account. This issue is fixed in version 1.0.0-rc.7. | |
| Title | New API: Admin can reset passkeys for same-level or higher-privileged users | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T16:06:38.718Z
Reserved: 2026-07-20T18:31:39.292Z
Link: CVE-2026-64866
No data.
Status : Received
Published: 2026-08-17T16:17:22.570
Modified: 2026-08-17T16:17:22.570
Link: CVE-2026-64866
No data.
OpenCVE Enrichment
Updated: 2026-08-17T17:30:18Z
Github GHSA