Improper access control in etcd - CVE-2026-44283
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to access unauthorized data.
The vulnerability exists due to improper access control in transaction operations when processing Put requests with PrevKv enabled. A remote attacker can send a specially crafted transaction request to access unauthorized data.
Kubernetes deployments that rely on the API server for authentication and authorization are not affected.