Severity: critical 

Affected versions:

- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6

Description:

The `deleteContainer` opcode (0x14/20) is processed without verifying the 
caller's ACL permissions, allowing any authenticated client to delete specific 
znodes in the data tree regardless of the ACL restrictions on the znode or its 
parent. This opcode is considered internal-only and the official client doesn't 
have API for it, but a client that can open a plain TCP session on the 
ZooKeeper client port (2181 by default) - with NO authentication and NO ACL 
permissions - can delete any empty persistent znode (including regular 
persistent nodes, container nodes, and TTL nodes) by issuing the raw protocol 
OpCode deleteContainer (20). The deleteContainer request path completely skips 
both the session check and the DELETE ACL check that are enforced by the 
regular delete (OpCode 2) path. This is an authorization bypass / ACL 
enforcement bug.

This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5, from 3.8.0 
through 3.8.6.

Users are recommended to upgrade to version 3.9.6 or 3.8.7, which fixes the 
issue.

Credit:

K <[email protected]> (reporter)
z f <[email protected]> (reporter)
布豪 <[email protected]> (finder)

References:

https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-79993

Reply via email to