CVE-2026-44283

NameCVE-2026-44283
Descriptionetcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1136829

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
etcd (PTS)bullseye3.3.25+dfsg-6vulnerable
bookworm3.4.23-4vulnerable
trixie3.5.16-4vulnerable
forky, sid3.5.16-11fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
etcdsource(unstable)3.5.16-111136829

Notes

[trixie] - etcd <no-dsa> (Minor issue)
[bookworm] - etcd <no-dsa> (Minor issue)
https://github.com/etcd-io/etcd/security/advisories/GHSA-x35m-3gp4-4fh5
https://github.com/etcd-io/etcd/pull/21677
https://github.com/etcd-io/etcd/pull/21680
Fixed by: https://github.com/etcd-io/etcd/commit/e8ce1ae41f18a938d0d8ad85dbc034c489e468db (v3.5.30)
Fixed by: https://github.com/etcd-io/etcd/commit/500c535adbb8a5a444bbff9fa34cc1c10addee71 (v3.5.30)

Search for package or bug name: Reporting problems