CVE-2026-32879
EUVD-2026-1452223.03.2026, 20:16
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion. As of time of publication, no known patched versions are available. Until a patched release is applied, do not rely on passkey as the step-up method for privileged secure-verification actions; require TOTP/2FA for those actions where operationally possible; or temporarily restrict access to affected secure-verification-protected endpoints.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| newapi | new_api | 0.10.0 ≤ 𝑥 < 0.11.9 |
| newapi | new_api | 0.11.9:alpha1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration