Improper Authentication in Traefik - #VU153911

 

Improper Authentication in Traefik - #VU153911

Published: October 7, 2026


Vulnerability identifier: #VU153911
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass a host's client certificate authentication.

The vulnerability exists due to improper authentication caused by TLS option name collisions in the Kubernetes Ingress NGINX provider when generating TLS options for Ingresses using the nginx.ingress.kubernetes.io/auth-tls-secret annotation. A remote attacker can present a client certificate issued by another host's certificate authority to bypass a host's client certificate authentication.

Exploitation requires resource names that collide when dots are replaced with dashes. The Ingress processed second reuses the TLS option generated for the first, causing its legitimate client certificates to be refused.


Affected software

Traefik

Remediation

Install security update from vendor's website.

Traefik - update to 3.7.14

External References

Related Security Bulletins