CVE-2026-33413Disclosure(etcd / etcd)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch etcd etcd systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call certain etcd functions in clusters that expose the gRPC API to untrusted or partially trusted clients. In unpatched etcd clusters with etcd auth enabled, unauthorized users are able to call MemberList and learn cluster topology, including member IDs and advertised endpoints; call Alarm, which can be abused for operational disruption or denial of service; use Lease APIs, interfering with TTL-based keys and lease ownership; and/or trigger compaction, permanently removing historical revisions and disrupting watch, audit, and recovery workflows. Kubernetes does not rely on etcd’s built-in authentication and authorization. Instead, the API server handles authentication and authorization itself, so typical Kubernetes deployments are not affected. Versions 3.4.42, 3.5.28, and 3.6.9 contain a patch. If upgrading is not immediately possible, reduce exposure by treating the affected RPCs as unauthenticated in practice. Restrict network access to etcd server ports so only trusted components can connect and/or require strong client identity at the transport layer, such as mTLS with tightly scoped client certificate distribution.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • etcd

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 2 mentions (2026-03-26); latest day: 1
  • 10 total mentions across 9 days

Affected systems

Vendors
Products
etcd

Deep dive

Activity timeline10 mentions / 9d
01122Mentions · 2026-03-25: 1Mentions · 2026-03-26: 2Mentions · 2026-03-29: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-04-22: 1Mentions · 2026-06-11: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-06-11: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-29: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-22: 103-2503-2603-2904-1304-1404-1504-2206-1108-27
Signal classification3 categories
Disclosure
770.0%
Patch
220.0%
General
110.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-251
Disclosure1
2026-03-262
Disclosure2
2026-03-291
Patch1
2026-04-131
Disclosure1
2026-04-141
Disclosure1
2026-04-151
Patch1
2026-04-221
Disclosure1
2026-06-111
Disclosure1
2026-08-271
General1
Full discourse10 posts
  • Strix@strix_ai
    Disclosure

    Strix found a critical auth bypass in etcd, one of the most used open-source components in cloud infrastructure. Now published as CVE-2026-33413 (CVSS 8.8). Read the full writeup: https://www.strix.ai/blog/where-others-missed-it-etcd-auth-bypass

    Post summary

    Strix AI discloses a critical authentication bypass in etcd (CVE-2026-33413) with a CVSS score of 8.8, and provides a detailed writeup for further analysis.

    1218057214.5K
    676 followersView on X
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    A list of CVE identifiers without any further detail or context.

    30124138.4K
    4.0K followersView on X
  • Densel@luckyhacker43
    Disclosure

    How Strix found a critical auth bypass in etcd 💥 🔗 https://www.strix.ai/blog/where-others-missed-it-etcd-auth-bypass 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-33413 Join team 👉https://t.me/luckyhacker43 https://t.co/F82DCWFJIA

    Post summary

    The tweet announces that Strix discovered a critical authentication bypass in etcd (CVE-2026-33413) and directs readers to a blog post for details, without providing technical specifics or patch information.

    0101212738
    2.8K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    etcd の認証バイパス脆弱性 CVE-2026-33413:機密クラスタ API への不正アクセス https://iototsecnews.jp/2026/04/14/critical-etcd-vulnerability-allows-unauthorized-access-to-sensitive-cluster-apis/ この脆弱性 CVE-2026-33413 は、システムの設計上の欠陥に起因します。 etcd では、認証や認可を担う authApplierV3 という仕組みがリクエストをチェックしていますが、一部の特定の命令に対する実装が欠落していました。そのため、本来は権限が必要な操作であっても、チェックをすり抜け、バックエンド実装へと直接命令が届いてしまう状態でした。プログラムのインターフェイスが共通化されていても、中身の実装が漏れてしまうと、意図しない動作を許してしまうことがあります。ご利用のチームは、ご注意ください。 #API #CVE202633413 #etcd #Vulnerability

    Post summary

    The post discloses a design flaw in etcd’s authApplierV3 that permits authentication bypass, allowing unauthorized operations on sensitive cluster APIs.

    01000101
    486 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical etcd vulnerability (CVE-2026-33413) allows unauthorized access to sensitive cluster APIs. Immediate patching recommended to secure your infrastructure. Link: https://thedailytechfeed.com/critical-etcd-vulnerability-cve-2026-33413-allows-unauthorized-api-access-urgent-update-recommended/ #Security #Vulnerability #API #Patch #Infrastructure #Cloud #Data #Breach #Network #Technology #IT #DevOps #Alert #Protection #Update #Software #Threat #Risk #Server #Access

    Post summary

    The tweet announces a critical CVE-2026-33413 that allows unauthorized access to etcd cluster APIs and urges users to apply patches immediately.

    000006
    279 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical etcd auth bypass CVE-2026-33413 with CVSS 8.8 exposes sensitive Kubernetes cluster APIs to unauthorized access across cloud-native deployments. https://threatcluster.io/cluster/critical-etcd-auth-bypass-vulnerability-exposes-cluster-apis-3b555191

    Post summary

    The tweet discloses the newly identified etcd authentication bypass (CVE‑2026‑33413) that exposes sensitive Kubernetes APIs to unauthorized access, highlighting its CVSS 8.8 score.

    0000031
    156 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33413 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication … https://www.cve.org/CVERecord?id=CVE-2026-33413

    Post summary

    The post announces an etcd authentication bypass vulnerability and lists the patched releases, but provides no PoC, exploit tools, or evidence of active exploitation.

    0000089
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33413 - High etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks a... https://www.thehackerwire.com/vulnerability/CVE-2026-33413/ https://t.co/ukGp7f0Ivo

    Post summary

    The tweet announces a newly disclosed high‑severity CVE‑2026‑33413 affecting etcd, noting that users can bypass authentication or authorization checks in older versions.

    0000044
    163 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33413 - etcd: Authorization bypasses in multiple APIs Intel Report: https://ift.tt/eN5YWyl

    Post summary

    The alert announces CVE‑2026‑33413, noting an authorization bypass in etcd APIs, but offers no PoC, exploit details, or patch information.

    0000027
    285 followersView on X
  • Daily AI Wire News@DailyAIWireNews
    Disclosure

    Open-Source AI Agent Uncovers Critical ETCD Vulnerability (CVE-2026-33413) (Source: Wiz) An open-source AI agent discovered a critical 8.8 CVSS vulnerability in etcd. #Cybersecurity #AIAgent #Vulnerability #ETCD #OpenSourceSecurity 🤔 As AI agents become more adept at finding vulnerabilities, how will this reshape the balance between offensive and defensive cybersecurity capabilities? https://s.dailyaiwire.news/3UpfS3

    Post summary

    An open‑source AI agent announced it had discovered a critical etcd vulnerability (CVE-2026-33413) with a CVSS score of 8.8, but no PoC, exploit, or patch details were provided.

    0000038
    573 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appetcdetcd---

Explore more