Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-64866— New API: Admin can reset passkeys for same-level or higher-privileged users

CVSS 5.1 · Medium EPSS 0.36% · P30

Affected Version Matrix 1

VendorProductVersion RangeStatus
QuantumNousnew-api>= 0.9.1.3, < 1.0.0-rc.7affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-64866

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
New API: Admin can reset passkeys for same-level or higher-privileged users
Source: CVE Program / CVE List V5
Vulnerability Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a lower-privileged administrator to remove a passkey from a same-level or higher-privileged account, including a root account. This issue is fixed in version 1.0.0-rc.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
QuantumNous New API 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
QuantumNous New API是QuantumNous个人开发者的一个LLM网关和AI资产管理系统。 QuantumNous New API 0.9.1.3至1.0.0-rc.7之前版本存在授权问题漏洞,该漏洞源于controller/passkey.go中的AdminResetPasskey对DELETE /api/user/:id/reset_passkey缺少canManageTargetRole授权检查,可能导致低权限管理员删除同级别或更高级别账户(包括root账户)的passkey。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
QuantumNousnew-api >= 0.9.1.3, < 1.0.0-rc.7 -

II. Public POCs for CVE-2026-64866

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64866

登录查看更多情报信息。

Patches & Fixes for CVE-2026-64866 (1)

Vendor Advisories for CVE-2026-64866 (1)

Vendor Pages for CVE-2026-64866 (1)

Same Patch Batch · QuantumNous · 2026-08-17 · 5 CVEs total

CVE-2026-648599.1 CRITICALNew API: User List API Leaks Root User Access Token Leading to Privilege Escalation
CVE-2026-714799.1 CRITICALNew API: Integer overflow in quota billing yields negative charges (self-crediting)
CVE-2026-648687.5 HIGHNew API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body rea
CVE-2026-648656.0 MEDIUMNew API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-64866

No comments yet


Leave a comment