Improper access control in etcd - CVE-2026-33413
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks and invoke restricted etcd API functions.
The vulnerability exists due to improper access control in the gRPC API layer when handling gRPC API requests from untrusted or partially trusted clients. A remote attacker can call MemberList, Alarm, Lease APIs, or trigger compaction to bypass authorization checks and invoke restricted etcd API functions.
The issue is exposed in clusters with etcd auth enabled that expose the gRPC API to untrusted or partially trusted clients.
Affected software
etcd (Red Hat package)
Red Hat OpenStack
How to mitigate CVE-2026-33413
etcd (Red Hat package) - update to 3.4.26-9.5.el9ost
Red Hat OpenStack - update to 17.1