Authentication Bypass Vulnerability in Traefik Detected by INCIBE

Published:
Illustrative image about Authentication Bypass Vulnerability in Traefik Detected by INCIBE

The National Cybersecurity Institute (INCIBE) has reported a critical vulnerability in Traefik, a popular reverse proxy and load balancing software. The Traefik authentication bypass detected allows an unauthenticated remote attacker to access protected resources through a specially crafted HTTP request.

Details of the Detected Vulnerability

The vulnerability, identified as CVE-2026-65600, affects the ReplacePathRegex middleware of Traefik. The flaw lies in a path traversal issue that occurs after the path is replaced using a vulnerable regular expression. Specifically, Traefik does not validate whether the resulting path changes when normalized, which may allow manipulated paths, such as /../admin, to be interpreted by backend applications as /admin.

As a result, an attacker can bypass the configured authentication mechanisms and access resources that should be protected. This vulnerability affects both read and write operations, including HTTP methods such as GET, POST, PUT, or DELETE on protected routes.

Affected Versions and Update Recommendations

Additional image about Authentication Bypass Vulnerability in Traefik Detected by INCIBE

The affected versions by this Traefik authentication bypass are:

  • Traefik version 1.7.34 and earlier
  • Traefik v2 versions 2.11.51 and earlier
  • Traefik v3 versions 3.6.22 and earlier, and from 3.7.0 to 3.7.6

To mitigate this vulnerability, INCIBE recommends updating to the following patched versions:

  • Traefik v2.11.52 or higher
  • Traefik v3.6.23 or higher
  • Traefik v3.7.7 or higher

In the case of the 1.x branch, no patched version is available. Therefore, it is advised to migrate to a supported version to avoid risks associated with this vulnerability.

Importance and Scope of the Vulnerability

The severity of this Traefik authentication bypass has been classified as critical, as it allows bypassing access controls without the need for credentials. The risk lies in the fact that a remote attacker can exploit this vulnerability to gain direct access to protected resources, which could compromise the security of applications and data hosted behind Traefik.

INCIBE has published this notice to alert administrators and security personnel to evaluate their infrastructure and apply the recommended updates as soon as possible.

Confirmation and Limitations of the Information

The information provided comes exclusively from the official INCIBE-CERT notice regarding the Traefik authentication bypass. No additional data is available on active exploitation cases or specific impacts in real environments.

Therefore, this news is limited to presenting the known facts and official recommendations, without being able to conclude on the existence of ongoing attacks or damages caused.

For more details, you can consult the official INCIBE notice.

Reviewed by
Published: 09/08/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
Responsible use of AI
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
Photo of Toni
Article author
Toni Berraquero

Toni Berraquero has trained since the age of 12 and has experience in retail, private security, ecommerce, digital marketing, marketplaces, automation and business tools.

View Toni’s profile

☕ If this genuinely helped…

You can support the project or share this article in one click. At least this block does something useful.