Skip to content
Multiple Vulnerabilities in Traefik and Grafana

Multiple Vulnerabilities in Traefik and Grafana

Csa.Sg • August 18, 2026

Attackers could exploit multiple vulnerabilities in Traefik and Grafana to spoof identities and escalate privileges. Patch promptly.

HPE has released security updates to address multiple vulnerabilities (CVE-2026-54763 and CVE-2026-33377) affecting Traefik and Grafana. These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of: CVE-2026-54763 at 8.8 and CVE-2026-33377 at 7.1, out of 10.

Successful exploitation of these vulnerabilities could lead to the following:

CVE-2026-54763: Due to improper handling of case sensitivity in the BasicAuth, DigestAuth, and ForwardAuth middlewares of Traefik, an authenticated attacker could inject underscore-variant headers to spoof identities or authorisation contexts on the affected backend system.

CVE-2026-33377: Due to improper access control in Grafana, an authenticated attacker with Editor-level write access could overwrite a dashboard not owned by them to escalate privileges on the affected dashboard.

These vulnerabilities affect the following products and versions:

CVE-2026-54763 (Traefik): versions prior to 2.11.51, 3.6.22, and 3.7.6

CVE-2026-33377 (Grafana): versions prior to 11.6.14, 12.2.8, 12.3.6, 12.4.3, and 13.0.1

Users and administrators of affected products are advised to update to the latest versions promptly.