CVE-2026-73499
etcd: Watch API authorization bypass through open-ended range requests
Technology
etcd
CVSS Score
7.1 / 10.0
Affected Versions
etcd before 3.5.33, 3.6.0 to 3.6.13, 3.7.0
Upstream Fix
3.5.33, 3.6.14, 3.7.1; no fix for 3.4 and earlier
Published
August 12, 2026
OSSeva Coverage
Fixed upstream
Description
A user granted READ on a single key can open a watch with clientv3.WithFromKey() and receive events for every key lexicographically at or after it. Range, Get and DeleteRange are not affected, and only clusters with authentication enabled are exposed. The affected range covers every release below 3.5.33, including the end-of-life 3.4 line. NVD has not analysed the record; the 7.1 score is the CVSS 4.0 score in the CNA record.
Is your etcd deployment affected?
If you're running etcd before 3.5.33, 3.6.0 to 3.6.13, 3.7.0, you need this patch. Book a discovery call to get covered.