SB2026012637 - Authentication bypass in Versa Concerto SD-WAN



SB2026012637 - Authentication bypass in Versa Concerto SD-WAN

Published: January 26, 2026

Security Bulletin ID SB2026012637
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper authentication (CVE-ID: CVE-2025-34026)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication checks in the Traefik reverse proxy configuration. A remote non-authenticated attacker can bypass authentication process and gain unauthorized access to administrative endpoints. The vulnerability allows an attacker to obtain heap dumps and trace logs and use this information to compromise the affected system. 


Remediation

Install update from vendor's website.