Authentication Bypass in Next.js Framework Affecting Vercel Applications
CVE-2026-64643

6.3MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64643?

The Next.js framework contains a vulnerability that allows for the bypassing of authentication within applications utilizing the App Router and Server Actions. This issue affects versions 12.0.0 up to 15.5.20 and 16.0.0 up to 16.2.10. Unsuspecting users can have access to Server Action IDs through publicly accessible client artifacts, such as static chunks comprised of action references. Although this vulnerability typically serves as a reconnaissance tool, its potential impact escalates when combined with other security weaknesses. The issue has been rectified in subsequent releases 15.5.21 and 16.2.11.

Affected Version(s)

next.js >= 13.0.0, < 15.5.21 < 13.0.0, 15.5.21

next.js >= 16.0.0, < 16.2.11 < 16.0.0, 16.2.11

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.