Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44283

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction operations involving PrevKv or lease attachment in Put requests, potentially leading to unauthorized data access or lease attachment.

Отчет

This flaw in etcd allows an authenticated user without sufficient read or lease-related permissions to bypass RBAC authorization checks when invoking transaction operations that include PrevKv or lease attachment in Put requests. This can lead to unauthorized data disclosure or lease attachment. The flaw is exploitable only when etcd's built-in authentication and RBAC are enabled and an attacker has valid etcd client credentials with direct access to the etcd gRPC API. Typical Red Hat OpenShift Container Platform deployments are not affected under default configuration, as the Kubernetes API server handles authentication and authorization independently of etcd's internal mechanisms.

Меры по смягчению последствий

For OpenShift Container Platform until an update can be applied, reduce exposure by restricting network access to etcd server ports so only trusted control-plane components can connect and require strong client identity at the transport layer, such as mTLS with tightly scoped client certificate distribution; these measures limit direct access to the etcd data store but do not replace applying the security update.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-etcd-rhel9Affected
Red Hat OpenStack Platform 16.2etcdUnder investigation
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-etcdAffected
Red Hat OpenStack Platform 17.1etcdUnder investigation
Red Hat OpenStack Platform 17.1rhosp-rhel9/openstack-etcdAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2477527etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access

EPSS

Процентиль: 13%
0.00225
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

ubuntu
3 месяца назад

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

nvd
3 месяца назад

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

CVSS3: 6.5
msrc
2 месяца назад

etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks

debian
3 месяца назад

etcd is a distributed key-value store for the data of a distributed sy ...

github
3 месяца назад

etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests

EPSS

Процентиль: 13%
0.00225
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2026-44283