CVE-2026-44283

medium
Published 2026-05-14 ยท Modified 2026-05-14
CVSS v3
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

Predictions

Exploit likelihood
53%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2026-44283 NameCVE-2026-44283 Descriptionetcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may beโ€ฆ

CVE-2026-44283

NameCVE-2026-44283
Descriptionetcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1136829

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
etcd (PTS)bullseye3.3.25+dfsg-6vulnerable
bookworm3.4.23-4vulnerable
trixie3.5.16-4vulnerable
forky3.5.16-10vulnerable
sid3.5.16-11fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
etcdsource(unstable)3.5.16-111136829

Notes

[trixie] - etcd <no-dsa> (Minor issue)
[bookworm] - etcd <no-dsa> (Minor issue)
https://github.com/etcd-io/etcd/security/advisories/GHSA-x35m-3gp4-4fh5
https://github.com/etcd-io/etcd/pull/21677
https://github.com/etcd-io/etcd/pull/21680
Fixed by: https://github.com/etcd-io/etcd/commit/e8ce1ae41f18a938d0d8ad85dbc034c489e468db (v3.5.30)
Fixed by: https://github.com/etcd-io/etcd/commit/500c535adbb8a5a444bbff9fa34cc1c10addee71 (v3.5.30)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - etcd <no-dsa> (Minor issue)[bookworm] - etcd <no-dsa> (Minor issue)https://github.com/etcd-io/etcd/security/advisories/GHSA-x35m-3gp4-4fh5https://github.com/etcd-io/etcd/pull/21677https://github.com/etcd-io/etcd/pull/21680Fixed by: https://github.com/etcd-io/etcd/commit/e8ce1ae41f18a938d0d8ad85dbc034c489e468db (v3.5.30)Fixed by: https://github.com/etcd-io/etcd/commit/500c535adbb8a5a444bbff9fa34cc1c10addee71 (v3.5.30)

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
windows Windows Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected โ€”
sid Fixed 3.5.16-11
forky Affected โ€”
bullseye Affected โ€”
bookworm Affected โ€”

Package impact

EcosystemPackageVulnerableFixed
golang Gogo.etcd.io/etcd/v3>=3.6.0,<3.6.113.6.11
golang Gogo.etcd.io/etcd/v3>=3.5.0,<3.5.303.5.30
golang Gogo.etcd.io/etcd<3.4.443.4.44
golang GOgo.etcd.io/etcd<= 3.4.433.4.44
golang GOgo.etcd.io/etcd/v3>= 3.5.0, <= 3.5.293.5.30
golang GOgo.etcd.io/etcd/v3>= 3.6.0, <= 3.6.103.6.11

Application impact

VendorProductVersionsFixed
etcdetcd{"endExcluding":"3.4.44"}3.4.44

References

CWEs

CWE-863

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.