CVE-2026-19906 | pkp pkp-lib 3.3.0/3.4.0/3.5.0 API Key Generation APIProfileForm.php setData apiKey entropy (Issue 12951)
A vulnerability categorized as problematic has been discovered in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argument apiKey can lead to insufficient entropy.
This vulnerability appears as CVE-2026-19906. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More