PT-2026-7893 · Traefik+2 · Traefik+2

Imlonghao

·

Published

2026-02-12

·

Updated

2026-04-16

·

CVE-2026-25748

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions authentik versions prior to 2025.10.4 authentik versions prior to 2025.12.4
Description authentik is an open-source identity provider. A malformed cookie could bypass authentication when using forward authentication with the authentik Proxy Provider in conjunction with Traefik or Caddy as a reverse proxy. The absence of authentik-specific X-Authentik-* headers with a malicious cookie could grant access to an attacker, depending on the application.
Recommendations Update to authentik version 2025.10.4 or later. Update to authentik version 2025.12.4 or later.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-AUTHENTIK-2026-25748
CVE-2026-25748
GHSA-FJ56-5763-J8PP

Affected Products

Caddy
Traefik
Authentik