Source: etcd
Version: 3.5.16-10
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for etcd.

CVE-2026-44283[0]:
| etcd is a distributed key-value store for the data of a distributed
| system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd
| allows read access via PrevKv, or lease attachment in Put requests
| within transaction operations, to bypass RBAC authorization checks.
| An authenticated user without sufficient read or lease-related
| permissions may be able to access unauthorized data or attach leases
| by invoking transaction operations with these features enabled. This
| vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-44283
    https://www.cve.org/CVERecord?id=CVE-2026-44283
[1] https://github.com/etcd-io/etcd/security/advisories/GHSA-x35m-3gp4-4fh5

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to