SB2026012637 - Authentication bypass in Versa Concerto SD-WAN
Published: January 26, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper authentication (CVE-ID: CVE-2025-34026)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication checks in the Traefik reverse proxy configuration. A remote non-authenticated attacker can bypass authentication process and gain unauthorized access to administrative endpoints. The vulnerability allows an attacker to obtain heap dumps and trace logs and use this information to compromise the affected system.
Remediation
Install update from vendor's website.