Authentication Bypass in Next.js Framework Affecting Vercel Applications
CVE-2026-64643
6.3MEDIUM
What is CVE-2026-64643?
The Next.js framework contains a vulnerability that allows for the bypassing of authentication within applications utilizing the App Router and Server Actions. This issue affects versions 12.0.0 up to 15.5.20 and 16.0.0 up to 16.2.10. Unsuspecting users can have access to Server Action IDs through publicly accessible client artifacts, such as static chunks comprised of action references. Although this vulnerability typically serves as a reconnaissance tool, its potential impact escalates when combined with other security weaknesses. The issue has been rectified in subsequent releases 15.5.21 and 16.2.11.
Affected Version(s)
next.js >= 13.0.0, < 15.5.21 < 13.0.0, 15.5.21
next.js >= 16.0.0, < 16.2.11 < 16.0.0, 16.2.11