Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
History

Sat, 05 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password. Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
Title Traefik before v2.11.55 Authentication Bypass via digestAuth Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
Title Traefik before v2.11.55 Authentication Bypass via digestAuth
First Time appeared Traefik
Traefik traefik
Weaknesses CWE-287
CPEs cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Vendors & Products Traefik
Traefik traefik
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-09-04T11:29:59.426Z

Updated: 2026-09-05T10:28:14.403Z

Reserved: 2026-09-04T10:59:00.162Z

Link: CVE-2026-85595

cve-icon Vulnrichment

Updated: 2026-09-04T13:56:18.601Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T12:17:22.960

Modified: 2026-09-08T20:10:30.270

Link: CVE-2026-85595

cve-icon Redhat

No data.