THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73421 — NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In mid

[NVD] CVE-2026-73421 — NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In mid

lownvdPublished 2026-08-13

CVE-2026-73421 CVSS: None Published: 2026-08-13T22:17:26.447

NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In middleware, Route Handlers, React Server Components, and oth

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73421