Vulnerability record · CVE-2025-34026 · published 21 May 2025
CVE-2025-34026: Versa Concerto authentication bypass in Traefik proxy exposes admin endpoints
Versa Networks · Concerto
Versa Concerto's Traefik reverse proxy configuration contains an authentication bypass (CWE-288) that lets an unauthenticated attacker reach administrative endpoints. The internal Actuator endpoint can then be used to obtain heap dumps and trace logs. It affects Concerto 12.1.2 through 12.2.0, with the vendor noting additional versions may be vulnerable.
Description
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass with high confidentiality impact, CISA KEV listing and very high EPSS probability.
What it is
Versa Concerto's Traefik reverse proxy configuration contains an authentication bypass (CWE-288) that lets an unauthenticated attacker reach administrative endpoints. The internal Actuator endpoint can then be used to obtain heap dumps and trace logs. It affects Concerto 12.1.2 through 12.2.0, with the vendor noting additional versions may be vulnerable.
Impact
An attacker gains unauthenticated access to administrative interfaces and can pull heap dumps and trace logs, which may expose credentials, session data and internal configuration. The CVSS 4.0 vector shows high confidentiality impact on both the vulnerable system and subsequent systems, with low integrity impact.
Attack surface
Reachable over the network via the Traefik reverse proxy with no authentication and no user interaction required (AV:N/PR:N/UI:N). Any internet- or network-exposed Concerto deployment running an affected version is in scope.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2026-01-22 with a 2026-02-12 remediation due date, and EPSS gives a 30-day probability of 0.8194 (99.6th percentile). A public third-party advisory is tagged as containing exploit and mitigation detail, so active exploitation should be assumed.
What to do
- Upgrade Concerto to a version above 12.2.0 or apply the vendor's fix from the Versa security portal advisory; confirm the exact fixed release with Versa since the record does not name one.
- If patching is not immediately possible, restrict network access to Concerto and its Traefik proxy to trusted management networks and disable or block the internal Actuator endpoint.
- Follow CISA BOD 22-01 guidance for cloud-hosted instances, including the option to discontinue use if mitigations are unavailable, by the 2026-02-12 due date.
- Rotate credentials, tokens and any secrets that may have been exposed through heap dumps or trace logs on potentially compromised instances.
- Review Traefik routing and middleware configuration for alternate-path bypasses and enforce authentication at the backend, not only at the proxy.
Detection
- Search proxy and Concerto access logs for unauthenticated requests to administrative paths and to Actuator endpoints such as /actuator, /actuator/heapdump and /actuator/httptrace.
- Alert on heap dump or trace log downloads and on unusual access to internal management paths from external or unexpected source IPs.
- Monitor for post-access activity such as new administrative accounts, configuration changes or outbound connections from Concerto hosts.
- Correlate Concerto host logs with network egress for data exfiltration following Actuator access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-34026 to the Known Exploited Vulnerabilities catalog on 22 January 2026 as "Versa Concerto Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 February 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce | ExploitMitigationThird Party Advisory |
| https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce | ExploitMitigationThird Party Advisory |
| https://security-portal.versa-networks.com/emailbulletins/6830f94328defa375486ff2e | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34026 | US Government Resource |
Track CVE-2025-34026 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-34026), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.