VYPR
Important severity8.2OSV Advisory· Published Jul 27, 2026

next: Next.js: Authentication bypass leading to unauthorized access

CVE-2026-64642

Description

next: Next.js: Authentication bypass leading to unauthorized access

Affected products

2
  • Vercel/Next.jsOSV2 versions
    v16.2.10, v16.2.9, v16.2.8, …+ 1 more
    • (no CPE)range: v16.2.10, v16.2.9, v16.2.8, …
    • (no CPE)

Patches

Vulnerability mechanics

News mentions

2