Skip to main content

Authentication Bypass Using an Alternate Path or Channel

CVE-2026-45109

Severity High
Score 7.5/10

Summary

Next.js is a React framework for building full-stack web applications. From 15.2.0 prior to 15.5.18 and 16.0.0 prior to 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-288 - Authentication Bypass Using an Alternate Path or Channel

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

References

Advisory Timeline

  • Published