CVE-2025-34026

Confirmed PUBLISHED

Versa Concerto Actuator Authentication Bypass Information Leak

Versa · Concerto

1 day faster than CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.2 Critical EPSS 83.5%

At a Glance

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

cisa nuclei_scanner
CVE Published
May 21, 2025
Exploitation Reported
Jun 01, 2026
CVSS
9.2 Critical
EPSS
83.5%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Versa
Concerto

12.1.2 to <= 12.2.0

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.