Back to VulnFeed / CVE-2026-45109
root@hackertop:~/vulnfeed/CVE-2026-45109#
CVE-2026-45109 MEDIUM Auth Bypass ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

next.js App Router Application authentication bypass

next.js 9d ago Impact pending confirmation
LIFECYCLE
5.1 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability was found in next.js (JavaScript Library) (the affected version unknown) and classified as critical. Affected by this issue is an unknown part of the component App Router Application. Upgrading eliminates this vulnerability.
Root Cause Analysis
Using CWE to declare the problem leads to CWE-288. A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Impact: Impacted is confidentiality.

Countermeasure: Upgrading eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-45109 · CVSS 5.1 · Active Threat