Improper access control in Next.js - CVE-2026-94485

 

Improper access control in Next.js - CVE-2026-94485

Published: October 2, 2026


Vulnerability identifier: #VU153128
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-94485
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in App Router metadata image routes when requesting metadata image URLs for dynamic segments deliberately excluded from generateStaticParams(). A remote attacker can request a metadata image URL for an excluded dynamic segment to disclose sensitive information.

The issue affects applications built with webpack.


Affected software

Next.js

How to mitigate CVE-2026-94485

Install security update from vendor's website.

Next.js - update to 16.3.8

External References

Related Security Bulletins