Authentication bypass using an alternate path or channel in Next.js - CVE-2026-44575
Published: May 6, 2026 / Updated: May 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose protected content.
The vulnerability exists due to authentication bypass using an alternate path or channel in middleware matchers for App Router applications when handling segment-prefetch and .rsc route variants. A remote attacker can send specially crafted segment-prefetch or .rsc requests to disclose protected content.
The issue affects applications that rely on middleware or proxy-based authorization checks for protection.
Affected software
Maximo Application Suite - Monitor Component
How to mitigate CVE-2026-44575
Maximo Application Suite - Monitor Component - addressed in versions 9.0.22, 9.1.12