Insufficient Entropy in API Key Generation of PKP Lib by Public Knowledge Project
CVE-2026-19906

6.3MEDIUM

Key Information:

Vendor

Pkp

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-19906?

A vulnerability has been discovered in the pkp-lib versions 3.3.0, 3.4.0, and 3.5.0 within the setData function of the APIProfileForm.php file. This issue pertains to the API Key Generation component, where manipulation of the apiKey argument can result in insufficient entropy. Although the complexity to exploit this vulnerability is high, it is important to note that the attack may be conducted remotely. The recommended mitigation is to apply patch 529b5df878e571ccc727647f7748eafc1466b041 to resolve the issue.

Affected Version(s)

pkp-lib 3.3.0

pkp-lib 3.4.0

pkp-lib 3.5.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Razielx64 (VulDB User)
.