CVE-2026-85594
Received Received - Intake

Traefik Kubernetes Ingress Middleware Credential Exposure

Vulnerability report for CVE-2026-85594, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulnCheck

Description

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
traefik traefik From 3.7.1 (inc)
traefik traefik From 3.7.1 (inc) to 3.7.12 (inc)
traefik traefik From 3.7.1 (inc) to 3.7.10 (inc)
traefik traefik 3.7.11

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in Kubernetes. This allows a namespace-limited tenant excluded from the allowlist to attach an operator-owned middleware to their Service. If the middleware injects backend credentials, an attacker could recover those credentials at a controlled backend.

Detection Guidance

To detect this vulnerability, check Traefik versions between v3.7.1 and v3.7.12 for the affected Kubernetes Ingress provider configuration. Inspect Service annotations for traefik.ingress.kubernetes.io/service.middlewares and verify if crossProviderNamespaces restrictions are enforced.

Impact Analysis

An attacker with low Kubernetes namespace privileges could attach a malicious middleware to a Service, potentially stealing backend credentials if the middleware injects them. This could lead to unauthorized access to sensitive data or systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected Traefik versions may face compliance violations and potential legal consequences.

Mitigation Strategies

Upgrade Traefik to version v3.7.11 or later to patch the vulnerability. Review and restrict Service annotations in the Kubernetes Ingress provider to prevent unauthorized middleware attachments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85594. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart