Executive brief
etcd is a critical distributed database used to store configuration and state data for large-scale systems like Kubernetes. A security flaw was discovered where the system fails to check if a user's security certificate has been revoked when using specific network settings. This could allow a previously authorized user or service, whose access was supposed to be cancelled, to continue accessing or modifying sensitive system data.
Technical details
A vulnerability exists in etcd's certificate validation logic when the '--listen-client-http-urls' flag is used to separate HTTP and gRPC traffic onto different listeners. In this configuration, the '--client-crl-file' (Certificate Revocation List) is only enforced on the HTTP listener and not the gRPC listener. An attacker possessing a revoked but otherwise valid certificate can bypass authentication controls to interact with the etcd cluster via gRPC. This issue is classified as Improper Certificate Validation (CWE-295) and is resolved in versions 3.5.32 and 3.6.13.
Affected products
- etcd-io etcd < 3.5.32, >= 3.6.0-alpha.0, < 3.6.13
Timeline
- 2026-07-01: patched: Fixes merged and releases v3.5.32 and v3.6.13 published.
- 2026-07-08: advisory: CVE-2026-59818 published.
References
- https://github.com/etcd-io/etcd/commit/2308ce1578064641d4d67c40f0487309267d1bef
- https://github.com/etcd-io/etcd/commit/24838af5a53dd0245adced920e42a9bf0e7a267f
- https://github.com/etcd-io/etcd/commit/8221ae82bc25d4d55ca64382207b69be71038cbb
- https://github.com/etcd-io/etcd/pull/22007
- https://github.com/etcd-io/etcd/pull/22021
- https://github.com/etcd-io/etcd/pull/22025
- https://github.com/etcd-io/etcd/releases/tag/v3.5.32