Attackers could exploit multiple vulnerabilities in Traefik and Grafana to spoof identities and escalate privileges. Patch promptly.
HPE has released security updates to address multiple vulnerabilities (CVE-2026-54763 and CVE-2026-33377) affecting Traefik and Grafana. These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of: CVE-2026-54763 at 8.8 and CVE-2026-33377 at 7.1, out of 10.
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-54763: Due to improper handling of case sensitivity in the BasicAuth, DigestAuth, and ForwardAuth middlewares of Traefik, an authenticated attacker could inject underscore-variant headers to spoof identities or authorisation contexts on the affected backend system.
CVE-2026-33377: Due to improper access control in Grafana, an authenticated attacker with Editor-level write access could overwrite a dashboard not owned by them to escalate privileges on the affected dashboard.
These vulnerabilities affect the following products and versions:
CVE-2026-54763 (Traefik): versions prior to 2.11.51, 3.6.22, and 3.7.6
CVE-2026-33377 (Grafana): versions prior to 11.6.14, 12.2.8, 12.3.6, 12.4.3, and 13.0.1
Users and administrators of affected products are advised to update to the latest versions promptly.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
