Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-73499

etcd: Watch API authorization bypass through open-ended range requests

Technology

etcd

CVSS Score

7.1 / 10.0

Affected Versions

etcd before 3.5.33, 3.6.0 to 3.6.13, 3.7.0

Upstream Fix

3.5.33, 3.6.14, 3.7.1; no fix for 3.4 and earlier

Published

August 12, 2026

OSSeva Coverage

Fixed upstream

Description

A user granted READ on a single key can open a watch with clientv3.WithFromKey() and receive events for every key lexicographically at or after it. Range, Get and DeleteRange are not affected, and only clusters with authentication enabled are exposed. The affected range covers every release below 3.5.33, including the end-of-life 3.4 line. NVD has not analysed the record; the 7.1 score is the CVSS 4.0 score in the CNA record.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.5.33, 3.6.0 to 3.6.13, 3.7.0, you need this patch. Book a discovery call to get covered.