THREAT OPS › Threat News › [NVD] CVE-2026-64859 (CRITICAL 9.1) — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized afte
[NVD] CVE-2026-64859 (CRITICAL 9.1) — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized afte
CVE-2026-64859 CVSS: 9.1 CRITICAL Published: 2026-08-17T16:17:22.280
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit("password"), allowing an authen
MITRE ATT&CK techniques
- Artificial IntelligenceT1588.007
Indicators of compromise
- CVE-2026-64859cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64859