Critical Auth Bypass Vulnerability in SUSE Elemental Systems (CVE-2026-33186)
ID: e73cd9b5-ca0c-51c2-ab3e-5472a5d97c31
STIX ID: report--e73cd9b5-ca0c-51c2-ab3e-5472a5d97c31
Feed Name: ThreatCluster
Threat Score
Critical authorization-bypass vulnerability CVE-2026-33186 affects SUSE Elemental components (elemental-system-agent, elemental-toolkit, elemental-register) due to improper HTTP/2 path pseudo-header validation in gRPC; a public proof-of-concept was released and patches were published on 2026-06-08 — apply updates immediately and monitor for anomalous gRPC/HTTP2 requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
