CVE-2026-44283
Published:May 14, 2026
Updated:May 18, 2026
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.
Affected Packages
go.etcd.io/etcd/v3 (GO):
Affected version(s) >=v3.6.0 <v3.6.11Fix Suggestion:
Update to version v3.6.11go.etcd.io/etcd/v3 (GO):
Affected version(s) >=v3.5.0 <v3.5.30Fix Suggestion:
Update to version v3.5.30go.etcd.io/etcd/v3 (GO):
Affected version(s) >=v3.5.0 <v3.5.30Fix Suggestion:
Update to version v3.5.30go.etcd.io/etcd (GO):
Affected version(s) >=v3.0.0+incompatible <v3.4.44Fix Suggestion:
Update to version v3.4.44go.etcd.io/etcd/v3 (GO):
Affected version(s) >=v3.6.0 <v3.6.11Fix Suggestion:
Update to version v3.6.11Related Resources (3)
Do you need more information?
Contact UsWeakness Type (CWE)
Incorrect Authorization
EPSS
Base Score:
0.03