PT-2026-93407 · Apache · Zookeeper+1

·

CVE-2026-59969

·

Published

2026-09-16

·

Updated

2026-09-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache ZooKeeper versions prior to 3.8.7 Apache ZooKeeper versions prior to 3.9.6
Description Quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket quorum path accepts a CA-trusted peer certificate whose Subject Alternative Name (SAN) does not match the connected host. This allows a malicious or misissued peer certificate to join quorum traffic, participate in leader election, and enter replication flows.
Recommendations Upgrade to version 3.8.7. Upgrade to version 3.9.6.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ZOOKEEPER-2026-59969
CLEANSTART-2026-QE83789
CVE-2026-59969

Affected Products

Apache Zookeeper
Zookeeper