Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44283

Опубликовано: 14 мая 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:*
Версия до 3.4.44 (исключая)
cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:*
Версия от 3.5.0 (включая) до 3.5.30 (исключая)
cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:*
Версия от 3.6.0 (включая) до 3.6.11 (исключая)

EPSS

Процентиль: 13%
0.00225
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

ubuntu
3 месяца назад

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

CVSS3: 5.4
redhat
3 месяца назад

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

CVSS3: 6.5
msrc
2 месяца назад

etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks

debian
3 месяца назад

etcd is a distributed key-value store for the data of a distributed sy ...

github
3 месяца назад

etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests

EPSS

Процентиль: 13%
0.00225
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863