Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-33413

etcd: unauthorized calls to MemberList, Alarm, Lease APIs and compaction

Technology

etcd

CVSS Score

8.8 / 10.0

Affected Versions

etcd before 3.4.42, 3.5.0 to 3.5.27, 3.6.0 to 3.6.8

Upstream Fix

3.4.42, 3.5.28, 3.6.9

Published

March 26, 2026

OSSeva Coverage

Fixed upstream

Description

In clusters with etcd authentication enabled, a shared flaw in the gRPC API layer lets unauthorized users call MemberList and learn the cluster topology, call Alarm to disrupt operations, use the Lease APIs and trigger compaction, which permanently removes historical revisions. The advisory says typical Kubernetes deployments are not affected, because the API server does its own authorization.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.4.42, 3.5.0 to 3.5.27, 3.6.0 to 3.6.8, you need this patch. Book a discovery call to get covered.