Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-33343

etcd: nested transactions bypass RBAC authorization

Technology

etcd

CVSS Score

6.5 / 10.0

Affected Versions

etcd before 3.4.42, 3.5.0 to 3.5.27, 3.6.0 to 3.6.8

Upstream Fix

3.4.42, 3.5.28, 3.6.9

Published

March 26, 2026

OSSeva Coverage

Fixed upstream

Description

An authenticated user whose RBAC permissions are limited to some key ranges can use nested transactions to bypass all key-level authorization and reach the whole data store. The advisory says typical Kubernetes deployments are not affected, because the API server does its own authorization.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.4.42, 3.5.0 to 3.5.27, 3.6.0 to 3.6.8, you need this patch. Book a discovery call to get covered.