PT-2026-26756 · Etcd · Etcd

Published

2026-01-01

·

Updated

2026-04-16

·

CVE-2026-33413

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions etcd versions prior to 3.4.42 etcd versions prior to 3.5.28 etcd versions prior to 3.6.9
Description Unauthorized users may bypass authentication or authorization checks to call specific functions in clusters that expose the gRPC API to untrusted or partially trusted clients. This allows attackers to call MemberList() to learn cluster topology, including member IDs and advertised endpoints, or call Alarm() to cause operational disruption or denial of service. Additionally, attackers can use Lease APIs to interfere with TTL-based keys and lease ownership, or trigger compaction to permanently remove historical revisions, which disrupts watch, audit, and recovery workflows. Typical Kubernetes deployments are not affected as the API server manages authentication and authorization independently.
Recommendations Update to version 3.4.42. Update to version 3.5.28. Update to version 3.6.9. Restrict network access to etcd server ports so only trusted components can connect. Require strong client identity at the transport layer, such as mTLS with tightly scoped client certificate distribution.

Exploit

Fix

DoS

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-ETCD-2026-33413
CVE-2026-33413
GHSA-Q8M4-XHHV-38MG
GO-2026-4806
OPENSUSE-SU-2026:10562-1

Affected Products

Etcd