CVE-2026-64866: New API: Admin can reset passkeys for same-level or higher-privileged users
The admin passkey reset endpoint lacked the role-level authorization check used by comparable privileged account-protection endpoints. A lower-privileged administrator could attempt passkey reset operations against same-level or higher-privileged users, including root-level accounts.
References
- github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3
- github.com/QuantumNous/new-api/pull/4929
- github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.7
- github.com/QuantumNous/new-api/security/advisories/GHSA-p845-629j-rcj6
- github.com/advisories/GHSA-p845-629j-rcj6
- nvd.nist.gov/vuln/detail/CVE-2026-64866
Code Behaviors & Features
Detect and mitigate CVE-2026-64866 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →