PT-2026-56612 · Etcd · Etcd

CVE-2026-59818

·

Published

2026-07-08

·

Updated

2026-07-14

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions etcd versions prior to 3.5.32 etcd versions prior to 3.6.13
Description etcd is a distributed key-value store for the data of a distributed system. When configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List (a list of digital certificates that have been revoked by the issuing certificate authority before their scheduled expiration date) is not enforced on the gRPC listener. This allows a client with a revoked certificate to authenticate successfully over gRPC.
Recommendations Update to version 3.5.32. Update to version 3.6.13.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92141
BIT-ETCD-2026-59818
CVE-2026-59818
GHSA-3WH4-J44W-PG92

Affected Products

Etcd