Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-85595: Traefik before 2.11.55 lets attackers skip login
CVE-2026-85595 · published 1 day ago
Summary
Versions of the Traefik web traffic manager older than 2.11.55 can allow anyone to get past the login screen that checks usernames and passwords. This could let an attacker reach parts of your website or services that should be private. Update Traefik to version 2.11.55 or a newer release right away.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| traefik | traefik |
< 2.11.55 <= 3.7.12 <= 3.7.10 |
Original advisory text
Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth
Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
References
Severity
9.3
Critical
Type
CWE-287Improper Authentication
Timeline
Published4 Sep 2026
Updated5 Sep 2026
First seen4 Sep 2026
Monitor software like this
Free during beta