PT-2026-56612 · Etcd · Etcd
CVE-2026-59818
·
Published
2026-07-08
·
Updated
2026-07-14
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
etcd versions prior to 3.5.32
etcd versions prior to 3.6.13
Description
etcd is a distributed key-value store for the data of a distributed system. When configured with
--listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List (a list of digital certificates that have been revoked by the issuing certificate authority before their scheduled expiration date) is not enforced on the gRPC listener. This allows a client with a revoked certificate to authenticate successfully over gRPC.Recommendations
Update to version 3.5.32.
Update to version 3.6.13.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etcd