CVE-2026-32879 is a logic flaw in New API's large language model (LLM) gateway and AI asset management system, affecting versions 0.10.0 and later. This vulnerability allows an authenticated user with a registered passkey to bypass full WebAuthn assertion for secure verification. Rated Medium (CVSS 4.9), it has a high impact on confidentiality and requires high privileges to exploit, but is network-exploitable with low attack complexity. There are no known exploits, active exploitation, or community discussion reported, and no patches are currently available. Organizations should temporarily restrict access to affected endpoints or require TOTP/2FA for privileged actions instead of relying on passkeys for step-up verification.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.10.0, < 0.11.9CPE matchmatch criteria | cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:* | ||
0.11.9CPE matchmatch criteria | cpe:2.3:a:newapi:new_api:0.11.9:alpha1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.