CVE-2026-85596
8.2Traefik · Traefik
Traefik versions 3.7.0 through 3.7.12 contain an authentication bypass in the Kubernetes Ingress provider that allows unauthorized access to routes requiring client certificate authentication.
Executive summary
A critical authentication bypass vulnerability in Traefik versions 3.7.0 through 3.7.12 allows unauthenticated attackers to access protected routes by triggering a TLS configuration conflict.
Vulnerability
The vulnerability stems from an improper authentication flaw (CWE-287) where conflicting TLS option names cause the system to fall back to a default configuration that lacks client certificate requirements. This enables an unauthenticated attacker to bypass mandatory client authentication for routes explicitly configured with strict verification.
Business impact
The exploitation of this flaw poses a severe risk to organizational security, as it effectively nullifies mutual TLS (mTLS) protections on affected ingress routes. With a CVSS score of 8.2, this high-severity vulnerability could lead to unauthorized access to sensitive internal services, potential data exfiltration, and a compromise of the overall zero-trust architecture within the Kubernetes environment.
Remediation
Immediate Action: Upgrade to Traefik version 3.7.13 or the latest available stable release to ensure the TLS option naming conflict is resolved and authentication enforcement is restored.
Proactive Monitoring: Review ingress controller logs for unexpected access patterns to services that are expected to require client certificates and monitor for TLS handshake failures or configuration warnings.
Compensating Controls: Implement network-level restrictions using Network Policies to limit access to sensitive ingress endpoints to known, trusted IP ranges while the update is being staged.
Exploitation status
Public Exploit Available: No confirmed public exploit (exploit_available is false).
Analyst recommendation
Given the high impact of bypassing client-side authentication, organizations must prioritize the immediate transition to the patched version of Traefik. Security teams should verify their Ingress configurations for any routes utilizing the affected NGINX annotations and ensure that the deployment lifecycle includes automated testing to confirm authentication enforcement post-upgrade.
More Traefik CVEs
Sources
Originally found and disclosed by james-yusuke, per the CVE Program record.
- GitHub Security Advisory (GHSA-j994-9gqj-9hwq) Vendor advisory
- VulnCheck Advisory: Traefik v3.7 Authentication Bypass via TLS Option Conflict Third-party advisory