CVE-2026-33413Missing Authorization in Etcd

Severity
8.8HIGHNVD
EPSS
0.0%
top 85.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 26
Latest updateApr 7

Description

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call certain etcd functions in clusters that expose the gRPC API to untrusted or partially trusted clients. In unpatched etcd clusters with etcd auth enabled, unauthorized users are able to call MemberList and learn cluster topology, including member IDs and advertised endpoints; call Alarm, which can be

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

Affected Packages4 packages

NVDetcd/etcd3.5.03.5.28+2
CVEListV5etcd-io/etcd< 3.4.42+2
Gogo.etcd.io/etcd_v33.5.0-alpha.03.5.28+2
Gogo.etcd.io/etcd3.3.27

🔴Vulnerability Details

5
OSV
Authorization bypasses in multiple APIs in go.etcd.io/etcd2026-04-07
OSV
CVE-2026-33413: etcd is a distributed key-value store for the data of a distributed system2026-03-26
CVEList
etcd: Authorization bypasses in multiple APIs2026-03-26
GHSA
etcd: Authorization bypasses in multiple APIs2026-03-20
OSV
etcd: Authorization bypasses in multiple APIs2026-03-20

📋Vendor Advisories

3
Red Hat
etcd: etcd: Authorization bypass allows information disclosure and denial of service2026-03-26
Microsoft
etcd: Authorization bypasses in multiple APIs2026-03-10
Debian
CVE-2026-33413: etcd - etcd is a distributed key-value store for the data of a distributed system. Prio...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-33413 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-33413 etcd: etcd: Authorization bypass allows information disclosure and denial of service2026-03-26
CVE-2026-33413 — Missing Authorization in Etcd-io Etcd | cvebase