PT-2026-93415 · Apache · Zookeeper+1
CVE-2026-79993
·
Published
2026-09-16
·
Updated
2026-09-29
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ZooKeeper versions 3.9.0 through 3.9.5
Apache ZooKeeper versions 3.8.0 through 3.8.6
Description
An authorization bypass exists where the
deleteContainer opcode (0x14/20) is processed without verifying the caller's Access Control List (ACL) permissions. This allows any client capable of opening a plain TCP session on the ZooKeeper client port to delete any empty persistent znode, including regular persistent nodes, container nodes, and TTL nodes, regardless of ACL restrictions on the znode or its parent. The deleteContainer request path bypasses both the session check and the DELETE ACL check required by the standard delete process. This opcode is intended for internal use and is not available via the official client API.Recommendations
Upgrade Apache ZooKeeper versions 3.9.0 through 3.9.5 to version 3.9.6.
Upgrade Apache ZooKeeper versions 3.8.0 through 3.8.6 to version 3.8.7.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Zookeeper
Zookeeper