Multiple security vulnerabilities affecting Apache ZooKeeper versions These security flaws impact Apache ZooKeeper versions 3 have been identified in Apache ZooKeeper versions 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5, which could allow unauthenticated attackers to delete critical nodes, falsify audit logs, or join TLS quorum replication streams. Consequently, these flaws threaten entire cloud data centers and disrupt critical application pipelines.
CVE-2026-79993 (CVSS 9.8 — Critical): An authorization bypass exists within an undocumented protocol handler, allowing unauthenticated attackers on client port 2181 to issue raw opcode requests to delete empty persistent znodes.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Apache ZooKeeper versions These security flaws impact Apache ZooKeeper versions 3 have been identified in Apache ZooKeeper versions 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5, which could allow unauthenticated attackers to delete critical nodes, falsify audit logs, or join TLS quorum replication streams. Consequently, these flaws threaten entire cloud data centers and disrupt critical application pipelines.
CVE-2026-79993 (CVSS 9.8 — Critical): An authorization bypass exists within an undocumented protocol handler, allowing unauthenticated attackers on client port 2181 to issue raw opcode requests to delete empty persistent znodes.[emaillocker id="1283"]
CVE-2026-59739 (CVSS 7.5 — High): Information disclosure occurs during client reconnection due to an incomplete previous patch in the watch management subsystem, enabling attackers to register existence watches on non-existent paths and discover restricted znode names.
CVE-2026-84439: Audit log injection is possible through unsanitized tab characters in digest authentication requests, allowing attackers to spoof audit results by injecting tabs that are parsed as legitimate field separators.
CVE-2026-59969: Rogue certificates can join quorum traffic when FIPS mode is active, permitting unauthorized access to sensitive data.
These vulnerabilities collectively present a significant risk to distributed systems relying on ZooKeeper for centralized service synchronization.
We recommend you to update Apache ZooKeeper to version 3.8.7.
The following reports contain further technical details:
[/emaillocker]