Junglewise Threat Intelligence

CVE-2025-34026: Versa Networks Concerto authentication bypass in Traefik configuration

CVE-2025-34026 · Severity: critical · CVSS 9.2 · Exploited in the wild · Published 2026-01-22

Executive brief

Versa Concerto, a platform used to manage and orchestrate SD-WAN networks, contains a security flaw that allows unauthorized individuals to bypass login requirements. By exploiting this vulnerability, an attacker can access administrative interfaces and sensitive internal logs or system memory data. This could lead to the exposure of network configurations and credentials, potentially compromising the entire managed network infrastructure.

Technical details

An authentication bypass vulnerability (CWE-288) exists in Versa Concerto due to a misconfiguration in the Traefik reverse proxy. A remote, unauthenticated attacker can exploit this flaw over the network to reach administrative endpoints that should be protected. Specifically, attackers can access the internal Spring Boot Actuator endpoint, which can be leveraged to extract heap dumps and trace logs. This exposure can lead to the theft of sensitive session information or credentials. The vulnerability has been observed being exploited in the wild and affects versions 11.4.0 through 12.2.0.

Affected products

  • Versa Networks Concerto 11.4.0 up to (excluding) 12.1.2, 12.1.2, 12.2.0

Timeline

  • 2025-05-21: disclosed: Initial vulnerability report and NVD publication
  • 2026-01-22: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2026-01-22: advisory: Vendor advisory published by Versa Networks