Ad

CVE-2026-32879

MEDIUM CVSS 3.1: 4.9 EPSS 0.04%
Updated Mar 25, 2026
Newapi
Parameter Value
CVSS 4.9 (MEDIUM)
Affected Versions 0.10.0 — 0.11.9
Fixed In 0.11.9
Type CWE-287 (Improper Authentication)
Vendor Newapi
Public PoC No

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion. As of time of publication, no known patched versions are available.

Until a patched release is applied, do not rely on passkey as the step-up method for privileged secure-verification actions; require TOTP/2FA for those actions where operationally possible; or temporarily restrict access to affected secure-verification-protected endpoints.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Newapi New_Api
cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:*
0.10.0 0.11.9
Newapi New_Api
cpe:2.3:a:newapi:new_api:0.11.9:alpha1:*:*:*:*:*:*

Related Vulnerabilities