CVE-2026-64859: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-
Summary
CVE-2026-64859 is a vulnerability in New API, an LLM gateway (a system that manages requests to language models) and AI asset management system, where versions before 1.0.0-rc.7 accidentally expose the root user's access token (a credential used to authenticate API requests) through admin APIs. An authenticated administrator could exploit this to gain unauthorized access to root-only system configuration APIs by obtaining the root user's bearer token (a type of access credential).
Solution / Mitigation
This issue is fixed in version 1.0.0-rc.7. Users should upgrade to version 1.0.0-rc.7 or later.
Vulnerability Details
9.1(critical)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
network
low
high
none
August 17, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64859
First tracked: August 17, 2026 at 02:09 PM
Classified by LLM (prompt v3) · confidence: 92%