logo

Critical etcd Auth Bypass Flaw Allows Unauthorized Access to Sensitive Cluster APIs

ID: 5d31e97c-da0a-50e7-8add-128f8dcc27a9

STIX ID: report--5d31e97c-da0a-50e7-8add-128f8dcc27a9

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Critical etcd Authentication Bypass (CVE-2026-33413)** — A high-severity (CVSS 8.8) auth bypass in etcd allows unauthenticated or underprivileged clients connecting to the gRPC client endpoint (typically port 2379) to call maintenance methods (Maintenance.Thealarm, KV.A compact, Lease.LeaseGrant) without proper authorization, enabling alarm manipulation, destructive premature compaction, and memory-exhausting lease creation; a Strix AI agent validated exploitability and the etcd team released a March 2026 patch to enforce missing admin permission checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.