{"id":"CVE-2026-64866","aliases":["GHSA-p845-629j-rcj6","GO-2026-6244"],"url":"https://o3.security/vulnerability/CVE-2026-64866","summary":"New API: Admin can reset passkeys for same-level or higher-privileged users","details":"## Summary\n\nThe admin passkey reset endpoint lacked the role-level authorization check used by comparable privileged account-protection endpoints. A lower-privileged administrator could attempt passkey reset operations against same-level or higher-privileged users, including root-level accounts.\n\n## Impact\n\nIf the target account had a passkey configured, a lower-privileged administrator could remove that authentication factor and weaken the target account's protection boundary. The attacker still needed administrator privileges, so the issue is rated Medium.\n\n## Affected versions\n\nThe vulnerable admin passkey reset behavior was present from the passkey feature introduction in `v0.9.1.3` through versions before `v1.0.0-rc.7`.\n\n## Patches\n\nThis issue is fixed in `v1.0.0-rc.7`. The fix adds a `canManageTargetRole` check to `AdminResetPasskey` before passkey lookup or deletion, preventing lower-privileged administrators from operating on same-level or higher-privileged users.\n\n## Workarounds\n\nIf upgrading immediately is not possible, restrict admin access to trusted operators only and block `DELETE /api/user/:id/reset_passkey` at the reverse proxy or gateway except for root operators.\n\n## References\n\n- Fixed by commit `0936e2504655a5cbf7bc3c388f6d3e2bb24916d3`.\n- Relevant code paths: `controller/passkey.go`, `controller/twofa.go`, and `router/api-router.go`.","published":"2026-08-17T16:06:38.718Z","modified":"2026-09-29T18:26:41.917212276Z","cvss":null,"epss":{"score":0.00363,"percentile":0.29923,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/QuantumNous/new-api","fixedVersion":"1.0.0-rc.7"}],"fix":{"url":"https://github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3","label":"QuantumNous/new-api@0936e25"},"references":[{"type":"WEB","url":"https://github.com/QuantumNous/new-api/releases/tag/v1.0.0-rc.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64866.json"},{"type":"ADVISORY","url":"https://github.com/QuantumNous/new-api/security/advisories/GHSA-p845-629j-rcj6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64866"},{"type":"FIX","url":"https://github.com/QuantumNous/new-api/commit/0936e2504655a5cbf7bc3c388f6d3e2bb24916d3"},{"type":"FIX","url":"https://github.com/QuantumNous/new-api/pull/4929"},{"type":"PACKAGE","url":"https://github.com/QuantumNous/new-api"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-29T18:26:41.917212276Z"}}