Cross-Provider Namespace Bypass in Traefik Ingress Kubernetes Service
CVE-2026-85594
7HIGH
What is CVE-2026-85594?
Traefik versions starting from v3.7.1 are susceptible to a bypass flaw related to crossProviderNamespaces restrictions on the service.middlewares annotation within the Kubernetes Ingress provider. This vulnerability allows an unauthorized tenant, which is not included in the allowed namespace list, to attach an operator-owned middleware to their Service. Consequently, if the injected middleware has access to backend credentials, it can recover these credentials from a controlled backend, posing a significant security risk.
Affected Version(s)
traefik 3.7.1 <= 3.7.12
