A vulnerability was found in vercel next.js up to 15.5.15/16.2.4 and classified as problematic. Impacted is an unknown function of the file /_next/data/.json. The manipulation results in incorrect authorization.

This vulnerability is cataloged as CVE-2026-44573. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.