CVE-2025-34026
KEV PoC moderateAuthentication Bypass in Versa Concerto SD-WAN Orchestration Platform (CVE-2025-34026)
CISA: Versa Concerto Improper Authentication Vulnerability
Versa Concerto, Versa Networks' SD-WAN orchestration and management platform, contains an authentication-bypass flaw (CWE-288) in its Traefik reverse proxy configuration that allows unauthenticated remote attackers to reach administrative endpoints that should require login. The flaw is network-reachable with no privileges or user interaction required, and the internal Actuator endpoint is also reachable, letting attackers pull heap dumps and trace logs that may contain sensitive information. Public research (Project Discovery) demonstrates the bypass can be chained toward remote code execution, and separate Versa Concerto flaws reported publicly have been shown to allow Docker escapes and compromise of the underlying host. Known-affected versions are Concerto 12.1.2 through 12.2.0, with additional versions possibly vulnerable, so any organization running a vulnerable Concerto instance — particularly one exposed to the internet — is at risk. The flaw is confirmed to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-01-22, and EPSS assigns an ~82% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade Concerto to the fixed release per Versa Networks' security advisory — the known-affected range is 12.1.2 through 12.2.0, but because additional versions may be vulnerable, confirm the patched version with the vendor; U.S. federal agencies must apply these mitigations or discontinue use of the product under BOD 22-01. In the meantime, restrict internet exposure of Concerto portals and its administrative/Actuator endpoints, and review trace logs and any evidence of heap-dump access for signs of unauthenticated administrative requests.
| Versa Networks Versa Concerto SD-WAN orchestration platform | 12.1.2 through 12.2.0 (additional versions may be vulnerable) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
- Affected
- Versa Concerto
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- versa-networks
- Products
- concerto
- Weakness
- CWE-288
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X