logo

Critical etcd Vulnerability Allows Unauthorized Access to Sensitive Cluster APIs

ID: 3c52f6f3-dc90-5a8c-ad78-c05f059d2df5

STIX ID: report--3c52f6f3-dc90-5a8c-ad78-c05f059d2df5

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** A critical authentication-bypass vulnerability (CVE-2026-33413, CVSS 8.8) was found in etcd allowing unauthenticated or under-privileged clients with network access to the client gRPC endpoint (port 2379) to trigger alarms, perform compaction, and create leases, potentially causing data loss and resource exhaustion; the issue was root-caused to missing auth-wrapper methods, validated end-to-end by an autonomous Strix AI agent, and fixed in the March 2026 security release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.