← Vulnerability feed

Vulnerability record · CVE-2026-59818 · published 8 July 2026

CVE-2026-59818: Etcd improper certificate validation vulnerability

Etcd · Etcd

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List is not enforced on the gRPC listener, allowing a client with a revoked certificate to authenticate successfully over gRPC. This issue is fixed in versions 3.5.32 and 3.6.13.

8.1 CVSS 3.1 High EPSS 0.43% · top 65.3% CWE-295 · Improper certificate validation
8.1CVSS 3.1 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References
13 Jul 2026Last modified by NVD

Description

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List is not enforced on the gRPC listener, allowing a client with a revoked certificate to authenticate successfully over gRPC. This issue is fixed in versions 3.5.32 and 3.6.13.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-59818 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-28235Etcd improper authentication vulnerabilityAuthentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.EPSS 1.6%8.8CVE-2026-33413Etcd missing authorization vulnerabilityetcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypas…EPSS 0.34%8.1CVE-2018-16886Etcd improper authentication vulnerabilityetcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is…EPSS 4.0%7.5CVE-2022-34038Etcd out-of-bounds write vulnerabilityEtcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that …EPSS 1.8%7.1CVE-2020-15113Etcd vulnerabilityIn etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatic…EPSS 0.23%6.5CVE-2026-33343Etcd incorrect authorization vulnerabilityetcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with R…EPSS 0.26%6.5CVE-2020-15112Etcd improper input validation vulnerabilityIn etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.…EPSS 1.3%6.5CVE-2020-15106Etcd improper input validation vulnerabilityIn etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-59818), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.