CVE-2025-34026 Details
Description
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
A vulnerability allowing authentication bypass has been identified in the Versa Concerto SD-WAN orchestration platform, specifically in versions 12.1.2 through 12.2.0. This vulnerability arises from inconsistencies in URL decoding within the Traefik reverse proxy configuration, enabling unauthorized access to administrative endpoints. Exploitation of this flaw can be achieved by omitting the 'X-Real-Ip' header, which is crucial for authentication checks on Actuator endpoints. As a result, attackers can access sensitive functionalities, such as heap dumps and trace logs, potentially leading to further exploitation.
Users are advised to apply the official patch released by Versa Concerto on May 24, 2025. Until then, temporary measures can be implemented at the reverse proxy or Web Application Firewall (WAF) levels, such as blocking requests with semicolons in the URL paths or dropping requests with 'Connection' headers that include 'X-Real-Ip'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce | CISA-ADP | ExploitMitigationThird Party Advisory |
| https://security-portal.versa-networks.com/emailbulletins/6830f94328defa375486ff2e | CISA-ADP | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34026 | CISA-ADP | US Government Resource |
| https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce | [email protected] | ExploitMitigationThird Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Versa Concerto Improper Authentication Vulnerability | Jan 22, 2026 | Feb 12, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| versa-networks concerto | >= 11.4.0, < 12.1.2 12.1.2 - 12.2.0 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Jan 23, 2026 | CVE Modified | CISA-ADP |
| Jan 22, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | CVE Modified | [email protected] |
| May 22, 2025 | CVE Modified | CISA-ADP |
| May 21, 2025 | New CVE Received | [email protected] |