Junglewise Threat Intelligence

CVE-2026-59818: etcd-io etcd improper certificate validation in gRPC listener

CVE-2026-59818 · Severity: medium · CVSS 6.5 · Published 2026-07-08

Technologies: Etcd-Io Etcd. Vendors: Etcd-Io.

Executive brief

etcd is a critical distributed database used to store configuration and state data for large-scale systems like Kubernetes. A security flaw was discovered where the system fails to check if a user's security certificate has been revoked when using specific network settings. This could allow a previously authorized user or service, whose access was supposed to be cancelled, to continue accessing or modifying sensitive system data.

Technical details

A vulnerability exists in etcd's certificate validation logic when the '--listen-client-http-urls' flag is used to separate HTTP and gRPC traffic onto different listeners. In this configuration, the '--client-crl-file' (Certificate Revocation List) is only enforced on the HTTP listener and not the gRPC listener. An attacker possessing a revoked but otherwise valid certificate can bypass authentication controls to interact with the etcd cluster via gRPC. This issue is classified as Improper Certificate Validation (CWE-295) and is resolved in versions 3.5.32 and 3.6.13.

Affected products

  • etcd-io etcd < 3.5.32, >= 3.6.0-alpha.0, < 3.6.13

Timeline

  • 2026-07-01: patched: Fixes merged and releases v3.5.32 and v3.6.13 published.
  • 2026-07-08: advisory: CVE-2026-59818 published.

References

Related threats