CVE-2026-33343Incorrect Authorization in Etcd

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 91.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 26
Latest updateApr 7

Description

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on key ranges can use nested transactions to bypass all key-level authorization. This allows any authenticated user with direct access to etcd to effectively ignore all key range restrictions, accessing the entire etcd data store. Kubernetes does not rely on etcd’s built-in authentication and authorization. Instead, the AP

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDetcd/etcd3.5.03.5.28+2
CVEListV5etcd-io/etcd< 3.4.42+2
Gogo.etcd.io/etcd_v33.6.0-alpha.03.6.9+2
Gogo.etcd.io/etcd3.3.27

🔴Vulnerability Details

5
OSV
Nested etcd transactions bypass RBAC authorization checks in go.etcd.io/etcd2026-04-07
CVEList
etcd: Nested etcd transactions bypass RBAC authorization checks2026-03-26
OSV
CVE-2026-33343: etcd is a distributed key-value store for the data of a distributed system2026-03-26
GHSA
etcd: Nested etcd transactions bypass RBAC authorization checks2026-03-20
OSV
etcd: Nested etcd transactions bypass RBAC authorization checks2026-03-20

📋Vendor Advisories

3
Red Hat
etcd: etcd: Authorization bypass allows information disclosure via nested transactions2026-03-26
Microsoft
etcd: Nested etcd transactions bypass RBAC authorization checks2026-03-10
Debian
CVE-2026-33343: etcd - etcd is a distributed key-value store for the data of a distributed system. Prio...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-33343 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-33343 — Incorrect Authorization in Etcd | cvebase