Insecure API Access in New API Gateway by QuantumNous
CVE-2026-64859

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-64859?

Prior to version 1.0.0-rc.7, the New API by QuantumNous exposes a significant vulnerability in its admin user list and user lookup APIs, specifically through the GET /api/user/ endpoint. This vulnerability allows an authenticated administrator to access the root user's bearer token due to improper serialization of User model objects, which inadvertently includes the User.AccessToken in the returned response. Such exposure can lead to unauthorized access to critical system configuration APIs. The issue has been addressed in the latest release, making it imperative for users to update to version 1.0.0-rc.7 or later to mitigate this risk.

Affected Version(s)

new-api < 1.0.0-rc.7

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.