# CVE-2026-85595

## Summary

- **CVE ID:** CVE-2026-85595
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-287
- **Published:** Sep 4, 2026
- **Last Modified:** Sep 5, 2026

## Description

Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.

## Affected Products

- traefik — traefik (0)
- traefik — traefik (2.11.55)
- traefik — traefik (3.0.0)

## References

- [CNA](https://github.com/traefik/traefik/security/advisories/GHSA-5w68-77r2-r64c)
- [CNA](https://www.vulncheck.com/advisories/traefik-before-2.11.55-authentication-bypass-via-digestauth)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.41%
- **EPSS Percentile:** 34.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._