logo

Critical Auth Bypass Vulnerability in SUSE Elemental Systems (CVE-2026-33186)

ID: e73cd9b5-ca0c-51c2-ab3e-5472a5d97c31

STIX ID: report--e73cd9b5-ca0c-51c2-ab3e-5472a5d97c31

Feed Name: ThreatCluster

Threat Score
74/100

Date Published: 2026-06-09

Date Updated: 2026-06-10

...
...

Critical authorization-bypass vulnerability CVE-2026-33186 affects SUSE Elemental components (elemental-system-agent, elemental-toolkit, elemental-register) due to improper HTTP/2 path pseudo-header validation in gRPC; a public proof-of-concept was released and patches were published on 2026-06-08 — apply updates immediately and monitor for anomalous gRPC/HTTP2 requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.