Improper Authentication in Traefik - #VU153912

 

Improper Authentication in Traefik - #VU153912

Published: October 7, 2026


Vulnerability identifier: #VU153912
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to impersonate a legitimate client and perform reads or writes with that client's permissions.

The vulnerability exists due to improper authentication isolation in Traefik's globally shared backend connection pool when reusing authenticated backend connections. A remote attacker can send requests over a separate frontend connection that is assigned a victim-authenticated backend socket to impersonate a legitimate client and perform reads or writes with that client's permissions.

Exploitation requires a connection-bound NTLM or SPNEGO/Kerberos Negotiate backend and a legitimate client that sends a valid Authorization: Negotiate token on its first request. The ordinary challenge-first authentication flow is not affected. The issue occurs on HTTP/1.1 and HTTP/2 frontend connections.


Affected software

Traefik

Remediation

Install security update from vendor's website.

Traefik - addressed in versions 2.11.58, 3.7.14

External References

Related Security Bulletins