CVE-2026-33343 describes an authorization bypass vulnerability in etcd versions prior to 3.4.42, 3.5.28, and 3.6.9. An authenticated user with low privileges can exploit this flaw via nested transactions to bypass key-level RBAC restrictions, gaining full read access to the entire etcd data store over the network with low complexity, resulting in a CVSS score of 6.5 (Medium). Importantly, typical Kubernetes deployments are not affected as they rely on their own authentication mechanisms, and patches are available. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.42CPE matchmatch criteria | cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:* | ||
>= 3.5.0, < 3.5.28CPE matchmatch criteria | cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:* | ||
>= 3.6.0, < 3.6.9CPE matchmatch criteria | cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.