Source: zookeeper
Version: 3.9.5-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for zookeeper.
CVE-2026-79993[0]:
| The `deleteContainer` opcode (0x14/20) is processed without
| verifying the caller's ACL permissions, allowing any authenticated
| client to delete specific znodes in the data tree regardless of the
| ACL restrictions on the znode or its parent. This opcode is
| considered internal-only and the official client doesn't have API
| for it, but a client that can open a plain TCP session on the
| ZooKeeper client port (2181 by default) - with NO authentication and
| NO ACL permissions - can delete any empty persistent znode
| (including regular persistent nodes, container nodes, and TTL nodes)
| by issuing the raw protocol OpCode deleteContainer (20). The
| deleteContainer request path completely skips both the session check
| and the DELETE ACL check that are enforced by the regular delete
| (OpCode 2) path. This is an authorization bypass / ACL enforcement
| bug. This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5,
| from 3.8.0 through 3.8.6. Users are recommended to upgrade to
| version 3.9.6 or 3.8.7, which fixes the issue.
CVE-2026-84439[1]:
| When audit logging is enabled (zookeeper.audit.enable=true), an
| unauthenticated attacker can inject arbitrary fields into Apache
| ZooKeeper's audit log by sending a digest authentication request
| with tab characters (\t) embedded in the username. Because the audit
| log uses tab-separated key=value format, the injected tabs are
| parsed as legitimate field separators, allowing the attacker to
| spoof audit results (e.g., injecting result=success), forge
| operation types, and corrupt forensic evidence. A log injection
| vulnerability in Apache ZooKeeper allows a client that can
| call setACL to inject forged key-value fields
| into zookeeper_audit.log. When audit logging is enabled, the server
| serializes attacker-controlled digest ACL ids into the acl= audit
| field without escaping tab characters. Because audit events are
| emitted as tab-separated key=value records, a crafted ACL id can
| make one successful setAcl event appear to contain forged fields
| such as operation=delete and znode=/forged. This undermines the
| integrity of downstream audit parsing, alerting, and incident
| response. This issue affects Apache ZooKeeper: from 3.9.0 through
| 3.9.5, from 3.8.0 through 3.8.6. Users are recommended to upgrade
| to version 3.9.6 or 3.8.7, which fixes the issue.
CVE-2026-84501[2]:
| An unauthenticated attacker can inject arbitrary fake log lines into
| Apache ZooKeeper's operational log by sending a crafted
| add_auth("ensemble", ...) request containing newline characters
| (\n). When the ensemble name doesn't match,
| EnsembleAuthenticationProvider.handleAuthentication() logs the raw,
| unsanitized name via LOG.warn(). Because SLF4J's {} placeholder
| preserves embedded newlines, the attacker can forge complete log
| entries — with arbitrary timestamps, log levels, class names, and
| messages — that are visually indistinguishable from genuine
| ZooKeeper log output. This issue affects Apache ZooKeeper: from
| 3.9.0 through 3.9.5, from 3.8.0 through 3.8.6. Users are
| recommended to upgrade to version 3.8.7 or 3.9.6, which fixes the
| issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-79993
https://www.cve.org/CVERecord?id=CVE-2026-79993
[1] https://security-tracker.debian.org/tracker/CVE-2026-84439
https://www.cve.org/CVERecord?id=CVE-2026-84439
[2] https://security-tracker.debian.org/tracker/CVE-2026-84501
https://www.cve.org/CVERecord?id=CVE-2026-84501
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore