PT-2026-93406 · Apache · Zookeeper+1

·

CVE-2026-59739

·

Published

2026-09-16

·

Updated

2026-10-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache ZooKeeper versions prior to 3.9.6 Apache ZooKeeper versions prior to 3.8.7
Description An information disclosure issue exists due to a missing Access Control List (ACL) check during the SetWatches reconnect replay. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths and then reconnecting after those paths are created with restricted ACLs. This occurs because the DataTree.setWatches() handler calls watcher.process(event) with a null ACL, bypassing the security check implemented in WatchManager.triggerWatch(). While the data within the znode is not exposed, the znode path itself may contain sensitive information such as usernames or login IDs.
Recommendations Upgrade to version 3.9.6. Upgrade to version 3.8.7.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ZOOKEEPER-2026-59739
CVE-2026-59739

Affected Products

Apache Zookeeper
Zookeeper