Executive brief
etcd is a critical database used to store configuration and state for distributed systems like Kubernetes. A security flaw allows a user who has permission to read just one specific piece of data to bypass security rules and monitor changes to all other data stored after that point. This could lead to the unauthorized exposure of sensitive system configurations or secrets to users who should not have access to them.
Technical details
An authorization bypass exists in etcd's RBAC enforcement for the Watch gRPC API. When a user is granted READ permission for a single exact key, they can initiate a watch request using the 'clientv3.WithFromKey()' option. This open-ended request allows the user to receive watch events for every key lexicographically greater than or equal to their permitted key, effectively bypassing intended access restrictions. The vulnerability only affects clusters with authentication enabled, as unauthenticated clusters already allow unrestricted access. Other operations like Range, Get, and DeleteRange are not affected. Patches are available in versions 3.5.33, 3.6.14, and 3.7.1.
Affected products
- etcd-io etcd < 3.5.33, >= 3.6.0, < 3.6.14, >= 3.7.0-alpha.0, < 3.7.1
Timeline
- 2026-07-23: disclosed
- 2026-07-24: advisory: GitHub Advisory published