{"id":"AZL-86898","summary":"CVE-2026-44283 affecting package etcd for versions less than 3.5.30-2","details":"etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.","modified":"2026-08-28T17:48:00.256003617Z","published":"2026-05-14T18:16:49Z","upstream":["CVE-2026-44283"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44283"}],"affected":[{"package":{"name":"etcd","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/etcd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.30-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86898.json"}}],"schema_version":"1.9.0"}