# Traefik security policy bypass flaw patched

Published: 2026-06-11 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/c4f463f1-b647-5045-b735-8ad3de6fd959/traefik-security-policy-bypass-flaw-patched

> A vulnerability in Traefik reverse proxy versions 3.6 and 3.7 can let attackers bypass security policy controls; patches are available.

ANSSI (CERT-FR) issued an advisory on a security policy bypass vulnerability affecting Traefik, the widely used cloud-native reverse proxy and load balancer. The flaw, tracked as CVE-2026-54761, impacts Traefik versions v3.6.20 and earlier in the 3.6 branch, and v3.7.4 and earlier in the 3.7 branch. Exploitation would allow an attacker to circumvent configured security policies, potentially exposing backend services or bypassing access controls enforced through Traefik.

The issue was disclosed by Traefik via GitHub Security Advisory GHSA-3g6v-2r68-prfc on June 11, 2026. Administrators running affected versions should upgrade to v3.6.21 or v3.7.5 as appropriate. No evidence of active exploitation is noted in the advisory; this is a vendor-driven patch notice rather than a confirmed in-the-wild attack.

## Mentioned in this report

- Vulnerabilities: CVE-2026-54761

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0738

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c4f463f1-b647-5045-b735-8ad3de6fd959/traefik-security-policy-bypass-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
