Insufficient Entropy in API Key Generation of PKP Lib by Public Knowledge Project
CVE-2026-19906
6.3MEDIUM
What is CVE-2026-19906?
A vulnerability has been discovered in the pkp-lib versions 3.3.0, 3.4.0, and 3.5.0 within the setData function of the APIProfileForm.php file. This issue pertains to the API Key Generation component, where manipulation of the apiKey argument can result in insufficient entropy. Although the complexity to exploit this vulnerability is high, it is important to note that the attack may be conducted remotely. The recommended mitigation is to apply patch 529b5df878e571ccc727647f7748eafc1466b041 to resolve the issue.
Affected Version(s)
pkp-lib 3.3.0
pkp-lib 3.4.0
pkp-lib 3.5.0
