What is CVE-2026-64643?
CVE-2026-64643 is an authentication bypass vulnerability in Next.js affecting versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10. Applications using App Router, Server Actions (use server), or use cache endpoints may expose protected page data without proper authentication. Immediate update to the patched version is required.
Azərbaycanca: CVE-2026-64643: Next.js framework-də autentifikasiya bypass zəifliyidir. Təsirə məruz qalan versiyalar 12.0.0–15.5.20 və 16.0.0–16.2.10 aralığıdır; App Router, Server Actions (use server) və ya use cache istifadə edən tətbiqlər üçün mühafizə olunan səhifələrin məlumatlarına icazəsiz çıxış imkanı yaradır. Təcili olaraq tövsiyə olunan sabit versiyaya yeniləmə etmək lazımdır.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which Next.js versions are affected by CVE-2026-64643?
The affected versions range from 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10.
Under what conditions can CVE-2026-64643 be exploited?
It can be exploited when the application uses App Router, Server Actions (use server), or use cache endpoints, potentially exposing protected page data without proper authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.