← Browse

CVE-2026-85595

High

High exploit probability or critical severity with a known exploit.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.4%
38.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-287
Published 2026-09-04 · modified 2026-09-16

Description

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.

Affected

traefik

References

Official: NVD · CVE.org