Executive brief
etcd is a critical database used to store and manage the configuration data for distributed systems like Kubernetes. A security flaw in its access control system could allow a user to read sensitive data or modify resource leases they should not have access to. While Kubernetes users are generally safe because they use a separate security layer, other systems relying on etcd's internal permissions should update to the latest version to prevent unauthorized data access.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in etcd's Role-Based Access Control (RBAC) implementation. The flaw is triggered when specific features, such as 'PrevKv' (previous key-value) or lease attachments, are used within 'Put' requests nested inside transaction operations. An authenticated attacker with limited permissions can exploit this to bypass authorization checks, allowing them to read unauthorized data or attach leases to keys. The vulnerability is resolved in versions 3.4.44, 3.5.30, and 3.6.11. Typical Kubernetes deployments are unaffected as they do not use etcd's native RBAC.
Affected products
- etcd-io etcd < 3.4.44, < 3.5.30, < 3.6.11
Timeline
- 2026-05-01: advisory: GitHub Security Advisory published
- 2026-05-14: disclosed: CVE published to NVD