Critical etcd Auth Bypass Flaw Allows Unauthorized Access to Sensitive Cluster APIs
ID: 5d31e97c-da0a-50e7-8add-128f8dcc27a9
STIX ID: report--5d31e97c-da0a-50e7-8add-128f8dcc27a9
Feed Name: cybersecurityNews.com
**Critical etcd Authentication Bypass (CVE-2026-33413)** — A high-severity (CVSS 8.8) auth bypass in etcd allows unauthenticated or underprivileged clients connecting to the gRPC client endpoint (typically port 2379) to call maintenance methods (Maintenance.Thealarm, KV.A compact, Lease.LeaseGrant) without proper authorization, enabling alarm manipulation, destructive premature compaction, and memory-exhausting lease creation; a Strix AI agent validated exploitability and the etcd team released a March 2026 patch to enforce missing admin permission checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
