Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-44283
Published:May 14, 2026
Updated:May 18, 2026
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.
Affected Packages
go.etcd.io/etcd/v3 (GO):
Affected version(s) >=v3.6.0 <v3.6.11
Fix Suggestion:
Update to version v3.6.11
go.etcd.io/etcd/v3 (GO):
Affected version(s) >=v3.5.0 <v3.5.30
Fix Suggestion:
Update to version v3.5.30
go.etcd.io/etcd/v3 (GO):
Affected version(s) >=v3.5.0 <v3.5.30
Fix Suggestion:
Update to version v3.5.30
go.etcd.io/etcd (GO):
Affected version(s) >=v3.0.0+incompatible <v3.4.44
Fix Suggestion:
Update to version v3.4.44
go.etcd.io/etcd/v3 (GO):
Affected version(s) >=v3.6.0 <v3.6.11
Fix Suggestion:
Update to version v3.6.11
Do you need more information?
Contact Us
Weakness Type (CWE)
Incorrect Authorization
EPSS
Base Score:
0.03