Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-44283

etcd: PrevKv and lease attachment in transactional Put bypass RBAC

Technology

etcd

CVSS Score

4.3 / 10.0

Affected Versions

etcd before 3.4.44, 3.5.0 to 3.5.29, 3.6.0 to 3.6.10

Upstream Fix

3.4.44, 3.5.30, 3.6.11

Published

May 14, 2026

OSSeva Coverage

Fixed upstream

Description

Reading the previous value with PrevKv, or attaching a lease, on a Put request inside a transaction skips RBAC checks, so an authenticated user without the read or lease permissions can read data or attach leases. The advisory says typical Kubernetes deployments are not affected, because the API server does its own authorization.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.4.44, 3.5.0 to 3.5.29, 3.6.0 to 3.6.10, you need this patch. Book a discovery call to get covered.