Improper access control in Traefik - #VU144549
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Kubernetes Ingress provider service middleware annotation handling when processing the traefik.ingress.kubernetes.io/service.middlewares Service annotation. A remote user can attach an operator-owned middleware from another provider to its own Service to disclose sensitive information.
Exploitation requires a namespace-limited tenant excluded from the allowlist and a security-sensitive middleware whose qualified name is known to the tenant.