Critical etcd Vulnerability Allows Unauthorized Access to Sensitive Cluster APIs
ID: 3c52f6f3-dc90-5a8c-ad78-c05f059d2df5
STIX ID: report--3c52f6f3-dc90-5a8c-ad78-c05f059d2df5
Feed Name: GBHackers
**Executive summary:** A critical authentication-bypass vulnerability (CVE-2026-33413, CVSS 8.8) was found in etcd allowing unauthenticated or under-privileged clients with network access to the client gRPC endpoint (port 2379) to trigger alarms, perform compaction, and create leases, potentially causing data loss and resource exhaustion; the issue was root-caused to missing auth-wrapper methods, validated end-to-end by an autonomous Strix AI agent, and fixed in the March 2026 security release.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
