CVE-2026-33413
etcd: unauthorized calls to MemberList, Alarm, Lease APIs and compaction
Technology
etcd
CVSS Score
8.8 / 10.0
Affected Versions
etcd before 3.4.42, 3.5.0 to 3.5.27, 3.6.0 to 3.6.8
Upstream Fix
3.4.42, 3.5.28, 3.6.9
Published
March 26, 2026
OSSeva Coverage
Fixed upstream
Description
In clusters with etcd authentication enabled, a shared flaw in the gRPC API layer lets unauthorized users call MemberList and learn the cluster topology, call Alarm to disrupt operations, use the Lease APIs and trigger compaction, which permanently removes historical revisions. The advisory says typical Kubernetes deployments are not affected, because the API server does its own authorization.
Is your etcd deployment affected?
If you're running etcd before 3.4.42, 3.5.0 to 3.5.27, 3.6.0 to 3.6.8, you need this patch. Book a discovery call to get covered.