CVE-2026-64642 | Vercel Next.js up to 16.2.10 App Router config.i18n locales improper authentication
A vulnerability categorized as critical has been discovered in Vercel Next.js up to 16.2.10. Affected by this issue is some unknown functionality of the file config.i18n of the component App Router. The manipulation of the argument locales results in improper authentication.
This vulnerability was named CVE-2026-64642. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.