Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN892
_____________________________________________________________________

DATE                : 16/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache ZooKeeper versions prior
                                     to 3.9.6, 3.8.7.
  
=====================================================================
https://lists.apache.org/thread/790yslgkd06z1l9zcozwt567yglqcp4r
https://lists.apache.org/thread/o21f094pojsqg8n6gogk4krzgmm3tvot
https://lists.apache.org/thread/v6nkx0r0flsjrqn57lc0tof6ltsszcx3
https://lists.apache.org/thread/t88mdco8cg59nrwvz8yftxo0fgboz5r3
https://lists.apache.org/thread/ckhj6lgfjtlkvotb77nyow21tyomy62s
_____________________________________________________________________


CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer
opcode allows unauthorized deletion of any empty persistent/container
znode


Severity: critical 

Affected versions:

- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6

Description:

The `deleteContainer` opcode (0x14/20) is processed without verifying
the caller's ACL permissions, allowing any authenticated client to
delete specific znodes in the data tree regardless of the ACL
restrictions on the znode or its parent. This opcode is considered
internal-only and the official client doesn't have API for it, but a
client that can open a plain TCP session on the ZooKeeper client port
(2181 by default) - with NO authentication and NO ACL permissions - can
delete any empty persistent znode (including regular persistent nodes,
container nodes, and TTL nodes) by issuing the raw protocol OpCode
deleteContainer (20). The deleteContainer request path completely skips
both the session check and the DELETE ACL check that are enforced by
the regular delete (OpCode 2) path. This is an authorization
bypass / ACL enforcement bug.

This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5, from
3.8.0 through 3.8.6.

Users are recommended to upgrade to version 3.9.6 or 3.8.7, which
fixes the issue.

Credit:

K <se...@outlook.com> (reporter)
z f <ti...@gmail.com> (reporter)
布豪 <19...@qq.com> (finder)

References:

https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-79993
_____________________________________________________________________

CVE-2026-59739: Apache ZooKeeper: Information disclosure via
SetWatches reconnect replay

Severity: critical 

Affected versions:

- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6

Description:

Information disclosure via SetWatches reconnect replay in Apache
ZooKeeper due to missing ACL check. An attacker can discover
ACL-restricted paths by registering exists-watches on non-existent
paths, then reconnecting after the paths are created with restricted
ACLs. Issue is caused by incomplete fix for CVE-2024-23944(
ZOOKEEPER-4799). The fix added ACL checking to
WatchManager.triggerWatch(). However, DataTree.setWatches() — the
SetWatches/SetWatches2 reconnect replay handler — still calls
watcher.process(event) with null ACL, bypassing the check entirely.
It's important to note that only the path is exposed by this
vulnerability, not the data of znode, but since znode path can
contain sensitive information like user name or login ID, this
issue is potentially critical.

Users are recommended to upgrade to version 3.9.6, 3.8.7 which
fixes the issue.

Credit:

NGUYEN HONG QUAN <ho...@gmail.com> (reporter)
n0mi1k <no...@gmail.com> (reporter)

References:

https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-59739

_____________________________________________________________________

CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized
output from multiple sources

Severity: important 

Affected versions:

- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6

Description:

When audit logging is enabled (zookeeper.audit.enable=true), an
unauthenticated attacker can inject arbitrary fields into Apache
ZooKeeper's audit log by sending a digest authentication request with
tab characters (\t) embedded in the username. Because the audit log uses
tab-separated key=value format, the injected tabs are parsed as
legitimate field separators, allowing the attacker to spoof audit
results (e.g., injecting result=success), forge operation types, and
corrupt forensic evidence.

A log injection vulnerability in Apache ZooKeeper allows a client that
can call setACL to inject forged key-value fields into
zookeeper_audit.log. When audit logging is enabled, the server
serializes attacker-controlled digest ACL ids into the acl= audit field
without escaping tab characters. Because audit events are emitted as
tab-separated key=value records, a crafted ACL id can make one successful
setAcl event appear to contain forged fields such as
operation=delete and znode=/forged. This undermines the integrity of
downstream audit parsing, alerting, and incident response.

This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5, from
3.8.0 through 3.8.6.

Users are recommended to upgrade to version 3.9.6 or 3.8.7, which
fixes the issue.

Credit:

Youlong Chen Institute of Computing Technology <ch...@ict.ac.cn>
(reporter)

References:

https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-84439

_____________________________________________________________________

CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate
with host mismatch in FIPS mode

Severity: important 

Affected versions:

- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6

Description:

Apache ZooKeeper quorum TLS fails to enforce peer hostname verification
in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true,
ssl.quorum.hostnameVerification=true, and
ssl.quorum.clientHostnameVerification=true are enabled, the Java
SSLSocket quorum path accepts a CA-trusted peer certificate whose SAN
does not match the connected host. A malicious or misissued peer
certificate can therefore join quorum traffic, participate in leader
election, and enter replication flows.


Users are recommended to upgrade to version 3.8.7 or 3.9.6, which
fixes the issue.

Credit:

Erichen <ch...@ict.ac.cn> (reporter)

References:

https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-59969

_____________________________________________________________________

CVE-2026-84501: Apache ZooKeeper: Operational log forgery via newline
injection in EnsembleAuthenticationProvider

Severity: moderate 

Affected versions:

- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6

Description:

An unauthenticated attacker can inject arbitrary fake log lines into
Apache ZooKeeper's operational log by sending a crafted
add_auth("ensemble", ...) request containing newline characters (\n).
When the ensemble name doesn't match,
EnsembleAuthenticationProvider.handleAuthentication() logs the raw,
unsanitized name via LOG.warn(). Because SLF4J's {} placeholder
preserves embedded newlines, the attacker can forge complete log
entries — with arbitrary timestamps, log levels, class names, and
messages — that are visually indistinguishable from genuine ZooKeeper
log output.

This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5,
from 3.8..0 through 3.8.6.

Users are recommended to upgrade to version 3.8.7 or 3.9.6,
which fixes the issue.

Credit:

Youlong Chen Institute of Computing Technology <ch...@ict.ac.cn>
(finder)

References:

https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-84501


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




