Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-33343
etcd: nested transactions bypass RBAC authorization
Technology
etcd
CVSS Score
6.5 / 10.0
Affected Versions
etcd before 3.4.42, 3.5.0 to 3.5.27, 3.6.0 to 3.6.8
Upstream Fix
3.4.42, 3.5.28, 3.6.9
Published
March 26, 2026
OSSeva Coverage
Fixed upstream
Description
An authenticated user whose RBAC permissions are limited to some key ranges can use nested transactions to bypass all key-level authorization and reach the whole data store. The advisory says typical Kubernetes deployments are not affected, because the API server does its own authorization.
Is your etcd deployment affected?
If you're running etcd before 3.4.42, 3.5.0 to 3.5.27, 3.6.0 to 3.6.8, you need this patch. Book a discovery call to get covered.