Critical etcd Auth Bypass Flaw Lets Attackers Access Sensitive Cluster APIs Without Authorization
ID: 85154726-f211-5f18-a424-891ac132cb2a
STIX ID: report--85154726-f211-5f18-a424-891ac132cb2a
Feed Name: Cyber Press
A critical authentication-bypass vulnerability (CVE-2026-33413, CVSS 8.8) was found in etcd's server-side authorization logic allowing unauthenticated or under-privileged requests to perform admin-level operations (e.g., Maintenance.Alarm, KV.Compact, Lease.LeaseGrant). The flaw was discovered and PoC-validated by an autonomous AI scanner called Strix, responsibly disclosed to the etcd team, and patched in March 2026; exploitation could enable data loss, denial-of-service via resource exhaustion, or masking of cluster alarms across Kubernetes and other systems that rely on etcd.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
