Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73499

Опубликовано: 12 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to receive watch events for every key lexicographically greater than or equal to the permitted key. In server/etcdserver/api/v3rpc/watch.go, the open-ended RangeEnd sentinel is rewritten before the RBAC permission check in server/auth/range_perm_cache.go function isRangeOpPermitted, causing the request to be treated as an exact-key watch. Range/Get and DeleteRange requests are not affected, and the issue affects only clusters with authentication enabled. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.

A flaw was found in etcd, a distributed key-value store. A user with READ permission on a single key can bypass authorization checks in the Watch gRPC API by using open-ended range requests. This allows them to receive watch events for keys beyond their authorized scope, leading to information disclosure. This issue affects clusters with authentication enabled.

Отчет

A flaw was found in etcd's Watch gRPC API. A user with READ permission on a single key can use open-ended range requests to bypass RBAC authorization and receive watch events for keys beyond their authorized scope, leading to information disclosure. This issue only affects etcd clusters with authentication enabled.

Меры по смягчению последствий

If etcd authentication is not required for the deployment, this vulnerability does not apply. For clusters with authentication enabled, restrict network-level access to the etcd gRPC API to trusted clients only, and audit user permissions to ensure the principle of least privilege.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/observatorium-rhel9Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform/platform-operator-bundleNot affected
Red Hat Ceph Storage 5rhceph/snmp-notifier-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-promtail-rhel9Not affected
Red Hat Ceph Storage 6rhceph/snmp-notifier-rhel9Not affected
Red Hat Ceph Storage 7rhceph/snmp-notifier-rhel9Not affected
Red Hat Ceph Storage 8rhceph/snmp-notifier-rhel9Not affected
Red Hat Ceph Storage 9rhceph/snmp-notifier-rhel10Not affected
Red Hat Hardened ImagesetcdNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-551
https://bugzilla.redhat.com/show_bug.cgi?id=2515005go.etcd.io/etcd: etcd: Information disclosure via Watch API authorization bypass

EPSS

Процентиль: 30%
0.00365
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
8 дней назад

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to receive watch events for every key lexicographically greater than or equal to the permitted key. In server/etcdserver/api/v3rpc/watch.go, the open-ended RangeEnd sentinel is rewritten before the RBAC permission check in server/auth/range_perm_cache.go function isRangeOpPermitted, causing the request to be treated as an exact-key watch. Range/Get and DeleteRange requests are not affected, and the issue affects only clusters with authentication enabled. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.

nvd
8 дней назад

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to receive watch events for every key lexicographically greater than or equal to the permitted key. In server/etcdserver/api/v3rpc/watch.go, the open-ended RangeEnd sentinel is rewritten before the RBAC permission check in server/auth/range_perm_cache.go function isRangeOpPermitted, causing the request to be treated as an exact-key watch. Range/Get and DeleteRange requests are not affected, and the issue affects only clusters with authentication enabled. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.

debian
8 дней назад

etcd is a distributed key-value store for the data of a distributed sy ...

github
27 дней назад

etcd: Watch API authorization bypass via open-ended range requests

EPSS

Процентиль: 30%
0.00365
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-73499