CVE-2026-19906: Insufficient Entropy in pkp pkp-lib
A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argument apiKey can lead to insufficient entropy. The attack may be performed from remote. This attack is characterized by high complexity. It is stated that the exploitability is difficult. This patch is called 529b5df878e571ccc727647f7748eafc1466b041. It is best practice to apply a patch to resolve this issue.
AI Analysis
Technical Summary
This vulnerability in pkp-lib (versions 3.3.0, 3.4.0, and 3.5.0) involves insufficient entropy during API key generation in the setData function of classes/user/form/APIProfileForm.php. An attacker manipulating the apiKey argument remotely could exploit this weakness, although the attack complexity is high and no privileges or user interaction are required. The vulnerability has a CVSS 4.0 base score of 6.3 (medium severity). A patch identified by commit 529b5df878e571ccc727647f7748eafc1466b041 addresses the issue.
Potential Impact
The vulnerability could allow an attacker to influence the entropy of API key generation, potentially weakening the randomness and security of generated API keys. This could reduce the effectiveness of authentication mechanisms relying on these keys. However, exploitation is considered difficult due to high attack complexity and no known exploits are reported in the wild.
Mitigation Recommendations
A patch identified by commit 529b5df878e571ccc727647f7748eafc1466b041 is available and it is best practice to apply this patch to resolve the issue. Patch status is not explicitly confirmed in the vendor advisory content, so users should verify the availability and applicability of this patch from the official pkp project resources.
CVE-2026-19906: Insufficient Entropy in pkp pkp-lib
Description
A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argument apiKey can lead to insufficient entropy. The attack may be performed from remote. This attack is characterized by high complexity. It is stated that the exploitability is difficult. This patch is called 529b5df878e571ccc727647f7748eafc1466b041. It is best practice to apply a patch to resolve this issue.
CVSS v4.0
Score 6.3medium
Affected software
cpe:2.3:a:pkp:pkp-lib:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in pkp-lib (versions 3.3.0, 3.4.0, and 3.5.0) involves insufficient entropy during API key generation in the setData function of classes/user/form/APIProfileForm.php. An attacker manipulating the apiKey argument remotely could exploit this weakness, although the attack complexity is high and no privileges or user interaction are required. The vulnerability has a CVSS 4.0 base score of 6.3 (medium severity). A patch identified by commit 529b5df878e571ccc727647f7748eafc1466b041 addresses the issue.
Potential Impact
The vulnerability could allow an attacker to influence the entropy of API key generation, potentially weakening the randomness and security of generated API keys. This could reduce the effectiveness of authentication mechanisms relying on these keys. However, exploitation is considered difficult due to high attack complexity and no known exploits are reported in the wild.
Mitigation Recommendations
A patch identified by commit 529b5df878e571ccc727647f7748eafc1466b041 is available and it is best practice to apply this patch to resolve the issue. Patch status is not explicitly confirmed in the vendor advisory content, so users should verify the availability and applicability of this patch from the official pkp project resources.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-14T19:48:10.879Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a80b9f2bf8831d5399481a0
Added to database: 08/15/2026, 19:11:46 UTC
Last enriched: 08/23/2026, 13:21:06 UTC
Last updated: 09/03/2026, 22:52:09 UTC
Views: 49
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.