CVE-2026-85594

Description

A flaw was found in Traefik. The software fails to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation within the Kubernetes Ingress provider. This vulnerability allows a namespace-limited tenant, even if excluded from the allowlist, to attach an operator-owned middleware to its Service. If this middleware injects backend credentials, the tenant can then recover these credentials at a controlled backend, leading to information disclosure.

Statement

A flaw was found in Traefik's Kubernetes Ingress provider (v3.7.1 through v3.7.10) where crossProviderNamespaces isolation is not enforced for the service.middlewares Service annotation. In multi-tenant Kubernetes clusters, an authenticated namespace-restricted tenant excluded from cross-namespace allowlists can attach operator-owned middlewares from external namespaces to their Service. If the attached middleware injects upstream backend credentials, the unauthorized tenant can intercept and recover those credentials at a tenant-controlled backend endpoint.

Mitigation

Restrict user permissions to modify Service annotations using Kubernetes Admission Controllers or Kyverno policies to prevent unauthorized referencing of traefik.ingress.kubernetes.io/service.middlewares. Alternatively, disable cross-provider namespace resolution in the Traefik Ingress provider configuration until patched.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.7N/AN/A
Attack VectorNetworkN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredLowN/AN/A
User InteractionNoneN/AN/A
ScopeChangedN/AN/A
ConfidentialityHighN/AN/A
Integrity ImpactNoneN/AN/A
Availability ImpactNoneN/AN/A

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability,Access Control

Technical Impact: Modify Memory; Read Memory; Execute Unauthorized Code or Commands; Gain Privileges or Assume Identity; Bypass Protection Mechanism; Other

Frequently Asked Questions

Want to get errata notifications? Sign up here.