Critical Vulnerabilities Found in Traefik and Grafana Require Immediate Patching

Critical Vulnerabilities Found in Traefik and Grafana Require Immediate Patching

First seen 18 Aug 2026, 10:06 UTC Csa.Sgnvd.nist.govsupport.hpe.com 85% similarity 72.0

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities have been identified in Traefik and Grafana, allowing attackers to spoof identities and escalate privileges. CVE-2026-54763, with a CVSS score of 8.8, affects Traefik's handling of authentication headers, enabling an authenticated attacker to inject malicious headers. CVE-2026-33377, scoring 7.1, allows an authenticated Grafana user with Editor access to overwrite dashboards not owned by them. These vulnerabilities affect specific versions of Traefik (prior to 2.11.51, 3.6.22, and 3.7.6) and Grafana (prior to 11.6.14, 12.2.8, 12.3.6, 12.4.3, and 13.0.1). Users are urged to update to the latest versions immediately to mitigate risks. Both vulnerabilities were published in 2026, with CVE-2026-54763 on July 6 and CVE-2026-33377 on May 13.

Key Points: • CVE-2026-54763 allows identity spoofing via manipulated authentication headers in Traefik. • CVE-2026-33377 enables privilege escalation in Grafana for users with Editor access. • Affected versions of Traefik and Grafana must be patched immediately to prevent exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-05-13
CVE-2026-33377 published
Grafana vulnerability allows privilege escalation for Editor-level users, affecting multiple versions.
nvd.nist.gov
2026-07-06
CVE-2026-54763 published
Traefik vulnerability allows identity spoofing through improper header handling, affecting specific versions.
nvd.nist.gov
2026-08-18
Security updates released
HPE released patches for both vulnerabilities; users are advised to update promptly to mitigate risks.
Csa.Sg

Community

Browse all →

Tracked Entities in This Story