PT-2026-93415 · Apache · Zookeeper+1

CVE-2026-79993

·

Published

2026-09-16

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache ZooKeeper versions 3.9.0 through 3.9.5 Apache ZooKeeper versions 3.8.0 through 3.8.6
Description An authorization bypass exists where the deleteContainer opcode (0x14/20) is processed without verifying the caller's Access Control List (ACL) permissions. This allows any client capable of opening a plain TCP session on the ZooKeeper client port to delete any empty persistent znode, including regular persistent nodes, container nodes, and TTL nodes, regardless of ACL restrictions on the znode or its parent. The deleteContainer request path bypasses both the session check and the DELETE ACL check required by the standard delete process. This opcode is intended for internal use and is not available via the official client API.
Recommendations Upgrade Apache ZooKeeper versions 3.9.0 through 3.9.5 to version 3.9.6. Upgrade Apache ZooKeeper versions 3.8.0 through 3.8.6 to version 3.8.7.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ZOOKEEPER-2026-79993
CLEANSTART-2026-VR96593
CVE-2026-79993

Affected Products

Apache Zookeeper
Zookeeper