PT-2026-51271 · Unknown · Centraldogma-Server

·

CVE-2026-11746

·

Published

2026-06-22

·

Updated

2026-09-11

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions centraldogma-server versions prior to 0.84.0
Description Enabling ZooKeeper replication without configuring the replication.secret variable causes the server to silently use a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, which allows an attacker with network access to read the complete replication log or join the quorum to execute arbitrary replicated commands across the cluster.
Recommendations Update to version 0.84.0 or later. Ensure the replication.secret variable is explicitly set when enabling ZooKeeper replication.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11746
GHSA-2J95-GQXF-V3VG

Affected Products

Centraldogma-Server