Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-44283
etcd: PrevKv and lease attachment in transactional Put bypass RBAC
Technology
etcd
CVSS Score
4.3 / 10.0
Affected Versions
etcd before 3.4.44, 3.5.0 to 3.5.29, 3.6.0 to 3.6.10
Upstream Fix
3.4.44, 3.5.30, 3.6.11
Published
May 14, 2026
OSSeva Coverage
Fixed upstream
Description
Reading the previous value with PrevKv, or attaching a lease, on a Put request inside a transaction skips RBAC checks, so an authenticated user without the read or lease permissions can read data or attach leases. The advisory says typical Kubernetes deployments are not affected, because the API server does its own authorization.
Is your etcd deployment affected?
If you're running etcd before 3.4.44, 3.5.0 to 3.5.29, 3.6.0 to 3.6.10, you need this patch. Book a discovery call to get covered.