{"data":{"id":"4143cced-3dfb-402c-b10a-6a35330a0447","title":"CVE-2026-64859: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-","summary":"CVE-2026-64859 is a vulnerability in New API, an LLM gateway (a system that manages requests to language models) and AI asset management system, where versions before 1.0.0-rc.7 accidentally expose the root user's access token (a credential used to authenticate API requests) through admin APIs. An authenticated administrator could exploit this to gain unauthorized access to root-only system configuration APIs by obtaining the root user's bearer token (a type of access credential).","solution":"This issue is fixed in version 1.0.0-rc.7. Users should upgrade to version 1.0.0-rc.7 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64859","publishedAt":"2026-08-17T16:17:22.280Z","cveId":"CVE-2026-64859","cweIds":["CWE-200"],"cvssScore":"9.1","cvssSeverity":"critical","severity":"critical","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["New API"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"high","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-17T16:17:22.280Z","capecIds":["CAPEC-116"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}