S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Sep 18, 2026

etcd RAFT Unauthenticated API Unauthenticated Access Scanner

This scanner detects the use of etcd RAFT Unauthenticated API Unauthenticated Access in digital assets. Unauthenticated access to the /v2/members endpoint discloses the full cluster membership list. Detecting such vulnerabilities helps secure your distributed system infrastructure.

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3
Times Used
continuous scan runs
3.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

etcd is widely used by companies to store critical configuration data in distributed systems and applications. It ensures development efficiency and reliable incident recovery through rapid data access and replication mechanisms. Organizations leverage etcd to support scalable, high-availability services and enhance workload automation. Due to its role, securing the API endpoints is crucial, as unprotected access could lead to unauthorized data retrieval and system compromise. Identifying unsecured etcd instances aids in maintaining system integrity and prevents possible disruptions. Properly configured, etcd enhances overall system sustainability and resilience.

The Unauthenticated Access vulnerability occurs when protection measures, like authentication, are absent from sensitive endpoints like etcd's /v2/members. Such vulnerabilities allow attackers to access potentially sensitive data without proper authorization. In this case, the flaw exposes the cluster membership list, enabling unauthorized enumeration of internal system components. Protecting such endpoints is essential for safeguarding against unwarranted access that could lead to more extensive system compromises. Prompt detection and remediation of such vulnerabilities are necessary to maintain a secure infrastructure environment.

The vulnerability allows attackers to access etcd's /v2/members endpoint without authentication, which should otherwise be restricted. This endpoint exposes critical information such as cluster member names, internal peer, and client URLs. Without adequate protection, anyone can exploit this information to further probe and potentially infiltrate the system. When the vulnerable endpoint is accessed, the data is returned as a JSON object, making it easier for attackers to parse and utilize. This lack of control can significantly increase the risk of unauthorized operations within the affected infrastructure.

Exploiting this vulnerability can have severe implications for a system's security and operational integrity. Unauthorized users may gain insights into the internal layout of the distributed system, facilitating further exploit attempts. Attackers might hijack exposed nodes, manipulate configurations, or even cause denial-of-service by overwhelming the system with requests. The disclosed information could additionally serve as a precursor for more targeted attacks, such as man-in-the-middle or replay attacks. Ensuring secure communication pathways and stringent access protocols are fundamental to avoiding such exploitations.

REFERENCES

Solution Advice
  • Disable the deprecated v2 API by setting `--enable-v2=false` in etcd version 3.4+.
  • Enable client authentication to ensure secure access control.
  • Implement RBAC for additional layer of security in access management.
  • Restrict network access to etcd's client interface to prevent direct unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.