CVE-2026-32879: New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure
Summary
A logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion.
Affected versions
= v0.10.0
Description
The POST /api/verify endpoint supports multiple secure verification methods, including passkeys. When the request body contains {"method":"passkey"}, the server only checks whether the authenticated account has a passkey record on file and then marks the secure verification session as complete. It does not verify that the requester successfully completed a WebAuthn assertion.
As a result, an authenticated user who already has a valid session and a registered passkey can satisfy the secure verification requirement without performing the intended passkey challenge/response flow.
Impact
In the upstream project, this issue affects actions protected by SecureVerificationRequired(). At the time of publication, the confirmed upstream impact is the root-only POST /api/channel/:id/key endpoint, which returns stored channel secrets.
Successful exploitation requires: - an already authenticated session for the target account, and - a registered passkey on that account.
No full login bypass or cross-account privilege escalation has been confirmed in the upstream codebase. However, the issue defeats the intended step-up verification control for affected privileged actions.
Workarounds
Until a patched release is applied: - do not rely on passkey as the step-up method for privileged secure-verification actions; - require TOTP/2FA for those actions where operationally possible; or - temporarily restrict access to affected secure-verification-protected endpoints.
Other sources
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion. As of time of publication, no known patched versions are available. Until a patched release is applied, do not rely on passkey as the step-up method for privileged secure-verification actions; require TOTP/2FA for those actions where operationally possible; or temporarily restrict access to affected secure-verification-protected endpoints.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32879?
CVE-2026-32879 is considered a critical vulnerability due to its potential for unauthorized access to sensitive channels.
How do I fix CVE-2026-32879?
To fix CVE-2026-32879, update the New API to version 0.10.1 or later where the vulnerability is addressed.
Who is affected by CVE-2026-32879?
CVE-2026-32879 affects all users of New API versions 0.10.0 and earlier that allow passkey-based secure verifications.
What type of vulnerability is CVE-2026-32879?
CVE-2026-32879 is a logic flaw vulnerability that allows bypassing secure verification for authenticated users.
What can attackers exploit in CVE-2026-32879?
Attackers can exploit CVE-2026-32879 to gain unauthorized access to root-only channels by bypassing WebAuthn assertions.