Apache ZooKeeper

5 known vulnerabilities in Apache ZooKeeper, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-84501 CVSS 5.3 medium An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted…
  • CVE-2026-84439 CVSS 5.3 medium When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache…
  • CVE-2026-79993 CVSS 7.5 high The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to…
  • CVE-2026-59969 CVSS 7.5 high Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true…
  • CVE-2026-59739 CVSS 7.5 high Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover…