etcd records
11 published records for vendor etcd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-287 Improper Authentication2
- CWE-863 Incorrect Authorization2
- CWE-862 Missing Authorization1
- CWE-295 Improper Certificate Validation1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-28235Proof of concept | Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.etcd · etcd · CWE-287 | Critical9.8 | — | 1.6% | Apr 4, 2023 |
35Monitor | CVE-2026-33413No exploit | etcd: Authorization bypasses in multiple APIsetcd · etcd · CWE-862 | High8.8 | — | 0.3% | Mar 26, 2026 |
33Monitor | CVE-2018-16886No exploit | etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control etcd · etcd · CWE-287 | High8.1 | — | 4.0% | Jan 14, 2019 |
32Monitor | CVE-2026-59818No exploit | etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocationetcd · etcd · CWE-295 | High8.1 | — | 0.4% | Jul 8, 2026 |
31Monitor | CVE-2022-34038No exploit | Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go.etcd · etcd · CWE-787 | High7.5 | — | 1.8% | Aug 22, 2023 |
28Monitor | CVE-2020-15113No exploit | Improper Preservation of Permissions in etcdetcd · etcd · CWE-281 | High7.1 | — | 0.2% | Aug 5, 2020 |
26Monitor | CVE-2020-15106No exploit | Improper Input Validation in etcdetcd · etcd · CWE-20 | Medium6.5 | — | 1.3% | Aug 5, 2020 |
26Monitor | CVE-2020-15112No exploit | Improper Input Validation in etcdetcd · etcd · CWE-20 | Medium6.5 | — | 1.3% | Aug 5, 2020 |
26Monitor | CVE-2026-33343No exploit | etcd: Nested etcd transactions bypass RBAC authorization checksetcd · etcd · CWE-863 | Medium6.5 | — | 0.3% | Mar 26, 2026 |
17Monitor | CVE-2023-32082No exploit | etcd key name can be accessed via LeaseTimeToLive APIetcd · etcd · CWE-200 | Medium4.3 | — | 0.7% | May 11, 2023 |
17Monitor | CVE-2026-44283No exploit | etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checksetcd · etcd · CWE-863 | Medium4.3 | — | 0.3% | May 14, 2026 |
- CVE-2021-2823539Monitor
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
CriticalCVSS 9.8Proof of conceptEPSS 2%etcd · etcdApr 4, 2023
- CVE-2026-3341335Monitor
etcd: Authorization bypasses in multiple APIs
HighCVSS 8.8No exploitEPSS 0%etcd · etcdMar 26, 2026
- CVE-2018-1688633Monitor
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control
HighCVSS 8.1No exploitEPSS 4%etcd · etcdJan 14, 2019
- CVE-2026-5981832Monitor
etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation
HighCVSS 8.1No exploitEPSS 0%etcd · etcdJul 8, 2026
- CVE-2022-3403831Monitor
Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go.
HighCVSS 7.5No exploitEPSS 2%etcd · etcdAug 22, 2023
- CVE-2020-1511328Monitor
Improper Preservation of Permissions in etcd
HighCVSS 7.1No exploitEPSS 0%etcd · etcdAug 5, 2020
- CVE-2020-1510626Monitor
Improper Input Validation in etcd
MediumCVSS 6.5No exploitEPSS 1%etcd · etcdAug 5, 2020
- CVE-2020-1511226Monitor
Improper Input Validation in etcd
MediumCVSS 6.5No exploitEPSS 1%etcd · etcdAug 5, 2020
- CVE-2026-3334326Monitor
etcd: Nested etcd transactions bypass RBAC authorization checks
MediumCVSS 6.5No exploitEPSS 0%etcd · etcdMar 26, 2026
- CVE-2023-3208217Monitor
etcd key name can be accessed via LeaseTimeToLive API
MediumCVSS 4.3No exploitEPSS 1%etcd · etcdMay 11, 2023
- CVE-2026-4428317Monitor
etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks
MediumCVSS 4.3No exploitEPSS 0%etcd · etcdMay 14, 2026