Answer in brief
CVE-2026-64866 records a Medium severity vulnerability in New API: Admin can reset passkeys for same-level or higher-privileged users. The current sources do not mark it as known exploited. The current feed maps QuantumNous/new-api (generic), github.com/QuantumNous/new-api (go), github.com/QuantumNous/new-api (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64866 records a Medium severity vulnerability in New API: Admin can reset passkeys for same-level or higher-privileged users. The current sources do not mark it as known exploited. The current feed maps QuantumNous/new-api (generic), github.com/QuantumNous/new-api (go), github.com/QuantumNous/new-api (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps QuantumNous/new-api (generic), github.com/QuantumNous/new-api (go), github.com/QuantumNous/new-api (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| QuantumNous/new-apigeneric | >= 0.9.1.3, < 1.0.0-rc.7 | Not reported |
| github.com/QuantumNous/new-apigo | >=0.9.1.3 <1.0.0-rc.7 | 1.0.0-rc.7 |
| github.com/QuantumNous/new-apigo | >=0.9.1.3,<1.0.0-rc.7 | 1.0.0-rc.7 |
Published upstream
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a lower-privileged administrator to remove a passkey from a same-level or higher-privileged account, including a root account. This issue is fixed in version 1.0.0-rc.7.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps QuantumNous/new-api (generic), github.com/QuantumNous/new-api (go), github.com/QuantumNous/new-api (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| QuantumNous/new-apigeneric | >= 0.9.1.3, < 1.0.0-rc.7 | Not reported |
| github.com/QuantumNous/new-apigo | >=0.9.1.3 <1.0.0-rc.7 | 1.0.0-rc.7 |
| github.com/QuantumNous/new-apigo | >=0.9.1.3,<1.0.0-rc.7 | 1.0.0-rc.7 |
Published upstream
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a lower-privileged administrator to remove a passkey from a same-level or higher-privileged account, including a root account. This issue is fixed in version 1.0.0-rc.7.
Quoted source text, attributed separately from HOL analysis.