CVE-2026-44283Medium· 4.3▾ SunlitA flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
4.3 → 0
medium → none
0 → 4.3
none → medium
4.3 → 0
medium → none
0 → 4.3
none → medium
4.3 → 0
medium → none
0 → 4.3
none → medium
Last analysed / modified upstream
A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction operations involving PrevKv or lease attachment in Put requests, potentially leading to unauthorized data access or lease attachment.
etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access — rated Moderate by Red Hat. Released 2026-05-14, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:44868
Workarounds / mitigations:
Affected packages:
go.etcd.io/etcd/v3 >= 3.6.0, < 3.6.11go.etcd.io/etcd/v3 >= 3.5.0, < 3.5.30go.etcd.io/etcd < 3.4.44Patched in:
go.etcd.io/etcd/v3 3.6.11go.etcd.io/etcd/v3 3.5.30go.etcd.io/etcd 3.4.44Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1313Medium· 6.5grafana: vulnerable to authorization bypass (CVE-2024-1313)
CVE-2026-34972Medium· 4.2github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls (CVE-2026-34972)
CVE-2026-37236Critical· 9.8grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control
CVE-2026-54770Medium· 6.1WebOb provides objects for HTTP requests and responses
CVE-2026-71491High· 7.5sqlparse is a non-validating SQL parser module for Python
CVE-2026-18620High· 7.1A flaw was found in Data Science Pipelines