PT-2026-93406 · Apache · Zookeeper+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ZooKeeper versions prior to 3.9.6
Apache ZooKeeper versions prior to 3.8.7
Description
An information disclosure issue exists due to a missing Access Control List (ACL) check during the SetWatches reconnect replay. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths and then reconnecting after those paths are created with restricted ACLs. This occurs because the
DataTree.setWatches() handler calls watcher.process(event) with a null ACL, bypassing the security check implemented in WatchManager.triggerWatch(). While the data within the znode is not exposed, the znode path itself may contain sensitive information such as usernames or login IDs.Recommendations
Upgrade to version 3.9.6.
Upgrade to version 3.8.7.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Zookeeper
Zookeeper