CVE-2025-34026HIGH 7.5CISA KEVEPSS p99.6%
CVE-2025-34026Versa Concerto Improper Authentication Vulnerability
Versa / Concerto
Description
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.
Scoring
| CVSS 3.1 | 7.5 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 83.38% probability of exploitation · percentile 99.6% · 2026-06-16T12:03:06Z |
| Published | 2025-05-21 |
| Last modified | 2026-01-23 |
CISA KEV entry
Added to KEV: 2026-01-22
Underlying weaknesses· 1
References
- https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce
- https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce
- https://security-portal.versa-networks.com/emailbulletins/6830f94328defa375486ff2e
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34026
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authentication Bypass Using an Alternate Path or Channelcwe-288 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Versa Concerto Improper Authentication Vulnerabilitykev-cve-2025-34026 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.