logo

Critical etcd Auth Bypass Flaw Lets Attackers Access Sensitive Cluster APIs Without Authorization

ID: 85154726-f211-5f18-a424-891ac132cb2a

STIX ID: report--85154726-f211-5f18-a424-891ac132cb2a

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: AnuPriya

...
...

A critical authentication-bypass vulnerability (CVE-2026-33413, CVSS 8.8) was found in etcd's server-side authorization logic allowing unauthenticated or under-privileged requests to perform admin-level operations (e.g., Maintenance.Alarm, KV.Compact, Lease.LeaseGrant). The flaw was discovered and PoC-validated by an autonomous AI scanner called Strix, responsibly disclosed to the etcd team, and patched in March 2026; exploitation could enable data loss, denial-of-service via resource exhaustion, or masking of cluster alarms across Kubernetes and other systems that rely on etcd.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.