Apache ZooKeeper
5 known vulnerabilities in Apache ZooKeeper, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-84501 CVSS 5.3 medium An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted…
- CVE-2026-84439 CVSS 5.3 medium When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache…
- CVE-2026-79993 CVSS 7.5 high The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to…
- CVE-2026-59969 CVSS 7.5 high Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true…
- CVE-2026-59739 CVSS 7.5 high Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover…