Improper Authentication in Traefik - CVE-2026-71326

 

Improper Authentication in Traefik - CVE-2026-71326

Published: August 21, 2026


Vulnerability identifier: #VU144548
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-71326
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to spoof an authenticated identity.

The vulnerability exists due to improper authentication in the BasicAuth middleware when deduplicating concurrent password verifications. A remote privileged user can send concurrent authentication requests with a colliding singleflight key to spoof an authenticated identity.

Exploitation requires knowledge of one valid credential and read access to the corresponding stored password hash. When the BasicAuth headerField option is enabled, the attacker-selected username is forwarded to the backend as a trusted identity.


Affected software

Traefik

How to mitigate CVE-2026-71326

Install security update from vendor's website.

Traefik - addressed in versions 3.6.25, 3.7.10

External References

Related Security Bulletins