← Vulnerability feed

Vulnerability record · CVE-2025-34026 · published 21 May 2025

CVE-2025-34026: Versa Concerto authentication bypass in Traefik proxy exposes admin endpoints

Versa Networks · Concerto

Versa Concerto's Traefik reverse proxy configuration contains an authentication bypass (CWE-288) that lets an unauthenticated attacker reach administrative endpoints. The internal Actuator endpoint can then be used to obtain heap dumps and trace logs. It affects Concerto 12.1.2 through 12.2.0, with the vendor noting additional versions may be vulnerable.

9.2 CVSS 4.0 Critical CISA KEV since 22 Jan 2026 EPSS 82% · top 0.4% CWE-288 · Authentication bypass via alternate path
9.2CVSS 4.0 base score
82%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable authentication bypass with high confidentiality impact, CISA KEV listing and very high EPSS probability.

What it is

Versa Concerto's Traefik reverse proxy configuration contains an authentication bypass (CWE-288) that lets an unauthenticated attacker reach administrative endpoints. The internal Actuator endpoint can then be used to obtain heap dumps and trace logs. It affects Concerto 12.1.2 through 12.2.0, with the vendor noting additional versions may be vulnerable.

Impact

An attacker gains unauthenticated access to administrative interfaces and can pull heap dumps and trace logs, which may expose credentials, session data and internal configuration. The CVSS 4.0 vector shows high confidentiality impact on both the vulnerable system and subsequent systems, with low integrity impact.

Attack surface

Reachable over the network via the Traefik reverse proxy with no authentication and no user interaction required (AV:N/PR:N/UI:N). Any internet- or network-exposed Concerto deployment running an affected version is in scope.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2026-01-22 with a 2026-02-12 remediation due date, and EPSS gives a 30-day probability of 0.8194 (99.6th percentile). A public third-party advisory is tagged as containing exploit and mitigation detail, so active exploitation should be assumed.

What to do

  • Upgrade Concerto to a version above 12.2.0 or apply the vendor's fix from the Versa security portal advisory; confirm the exact fixed release with Versa since the record does not name one.
  • If patching is not immediately possible, restrict network access to Concerto and its Traefik proxy to trusted management networks and disable or block the internal Actuator endpoint.
  • Follow CISA BOD 22-01 guidance for cloud-hosted instances, including the option to discontinue use if mitigations are unavailable, by the 2026-02-12 due date.
  • Rotate credentials, tokens and any secrets that may have been exposed through heap dumps or trace logs on potentially compromised instances.
  • Review Traefik routing and middleware configuration for alternate-path bypasses and enforce authentication at the backend, not only at the proxy.

Detection

  • Search proxy and Concerto access logs for unauthenticated requests to administrative paths and to Actuator endpoints such as /actuator, /actuator/heapdump and /actuator/httptrace.
  • Alert on heap dump or trace log downloads and on unusual access to internal management paths from external or unexpected source IPs.
  • Monitor for post-access activity such as new administrative accounts, configuration changes or outbound connections from Concerto hosts.
  • Correlate Concerto host logs with network egress for data exfiltration following Actuator access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-34026 to the Known Exploited Vulnerabilities catalog on 22 January 2026 as "Versa Concerto Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 February 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34026 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-34027Versa Concerto auth bypass and TOCTOU race leading to RCEVersa Concerto's Traefik reverse proxy configuration contains an authentication bypass that lets an unauthenticated attacker reach administrative end…EPSS 45%analysed8.6CVE-2025-34025Versa-networks concerto incorrect permission assignment vulnerabilityThe Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe defaul…EPSS 0.61%10.0CVE-2026-20079Cisco Secure Firewall Management Center authentication bypass to rootCisco Secure Firewall Management Center (FMC) Software contains an authentication bypass caused by an improper system process created at boot time. A…KEVEPSS 88%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed8.2CVE-2026-18556N-able N-central authentication bypass via alternate pathN-able N-central contains an authentication bypass (CWE-288) that lets an attacker reach protected functionality through an alternate path or channel…KEVEPSS 7.9%analysed8.2CVE-2026-18577N-able N-central incomplete patch enables auth bypass and account takeoverAn incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the origina…KEVEPSS 15%analysed7.5CVE-2026-1603Ivanti Endpoint Manager authentication bypass leaks stored credentialsIvanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a func…KEVEPSS 88%analysed9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed

Source: NIST National Vulnerability Database (record CVE-2025-34026), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.