# Traefik 3.7.x auth bypass patched

Published: 2026-06-19 · Severity: high
Canonical: https://vorant.io/reports/71f62885-99f2-5640-824e-afe3f3796186/traefik-3-7-x-auth-bypass-patched

> A security policy bypass vulnerability in Traefik versions 3.7.x before 3.7.5 allows attackers to circumvent authentication controls.

CERT-FR has issued an advisory for a security policy bypass vulnerability affecting Traefik proxy versions 3.7.x prior to 3.7.5. The flaw, tracked as CVE-2026-54762, enables attackers to circumvent security policies implemented within the reverse proxy and load balancer.

Traefik is widely deployed in cloud-native environments and Kubernetes clusters to route HTTP/HTTPS traffic. A bypass vulnerability in such a critical access-control component could allow unauthorized access to backend services that should be protected by authentication or authorization policies. Organizations running affected versions should prioritize patching to version 3.7.5 or later.

The vendor has published a security advisory (GHSA-4mr2-fg2p-w63c) with remediation guidance. No active exploitation has been reported in the advisory, but the exposure window and deployment footprint warrant prompt attention.

## Mentioned in this report

- Vulnerabilities: CVE-2026-54762

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0785/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/71f62885-99f2-5640-824e-afe3f3796186/traefik-3-7-x-auth-bypass-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
