Threats Tagged 'ghsa-p845-629j-rcj6'
View all threats tagged with 'ghsa-p845-629j-rcj6'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-p845-629j-rcj6'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-64866: CWE-862: Missing Authorization in QuantumNous new-apiCVE-2026-64866 0 ## Summary The admin passkey reset endpoint lacked the role-level authorization check used by comparable privileged account-protection endpoints. A lower-privileged administrator could attempt passkey reset operations against same-level or higher-privileged users, including root-level accounts. ## Impact If the target account had a passkey configured, a lower-privileged administrator could remove that authentication factor and weaken the target account's protection boundary. The attacker still needed administrator privileges, so the issue is rated Medium. ## Affected versions The vulnerable admin passkey reset behavior was present from the passkey feature introduction in `v0.9.1.3` through versions before `v1.0.0-rc.7`. ## Patches This issue is fixed in `v1.0.0-rc.7`. The fix adds a `canManageTargetRole` check to `AdminResetPasskey` before passkey lookup or deletion, preventing lower-privileged administrators from operating on same-level or higher-privileged users. ## Workarounds If upgrading immediately is not possible, restrict admin access to trusted operators only and block `DELETE /api/user/:id/reset_passkey` at the reverse proxy or gateway except for root operators. ## References - Fixed by commit `0936e2504655a5cbf7bc3c388f6d3e2bb24916d3`. - Relevant code paths: `controller/passkey.go`, `controller/twofa.go`, and `router/api-router.go`. Join the discussion | CVE Database V5 | 08/17/2026, 16:36:05 UTC Added: 08/17/2026, 16:27:58 UTC |
Showing 1 to 1 of 1 result