{"id":"GO-2026-4808","summary":"Nested etcd transactions bypass RBAC authorization checks in go.etcd.io/etcd","details":"Nested etcd transactions bypass RBAC authorization checks in go.etcd.io/etcd","aliases":["BIT-etcd-2026-33343","CVE-2026-33343","GHSA-rfx7-8w68-q57q"],"modified":"2026-04-10T08:29:31.267011739Z","published":"2026-04-07T14:58:41Z","related":["CGA-mc2m-wghc-m2wq"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-4808","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/etcd-io/etcd/security/advisories/GHSA-rfx7-8w68-q57q"}],"affected":[{"package":{"name":"go.etcd.io/etcd","ecosystem":"Go","purl":"pkg:golang/go.etcd.io/etcd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4808.json"}},{"package":{"name":"go.etcd.io/etcd/v3","ecosystem":"Go","purl":"pkg:golang/go.etcd.io/etcd/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.4.42"},{"introduced":"3.5.0-alpha.0"},{"fixed":"3.5.28"},{"introduced":"3.6.0-alpha.0"},{"fixed":"3.6.9"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4808.json"}}],"schema_version":"1.7.5"}