PT-2026-93417 · Apache · Zookeeper+1
CVE-2026-84439
·
Published
2026-09-16
·
Updated
2026-09-19
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ZooKeeper versions 3.9.0 through 3.9.5
Apache ZooKeeper versions 3.8.0 through 3.8.6
Description
Log injection occurs when audit logging is enabled via
zookeeper.audit.enable=true. An unauthenticated attacker can inject arbitrary fields into the audit log by sending a digest authentication request containing tab characters (t) in the username. Additionally, a client capable of calling the setACL() function can inject forged key-value fields into the zookeeper audit.log because the server fails to escape tab characters when serializing digest ACL ids into the acl field. Since the audit log uses a tab-separated key=value format, these injected tabs are interpreted as legitimate separators, allowing attackers to spoof results (e.g., result=success), forge operation types (e.g., operation=delete), and corrupt forensic evidence, which compromises downstream audit parsing and incident response.Recommendations
Upgrade Apache ZooKeeper versions 3.9.0 through 3.9.5 to version 3.9.6.
Upgrade Apache ZooKeeper versions 3.8.0 through 3.8.6 to version 3.8.7.
As a temporary mitigation, consider disabling the
zookeeper.audit.enable setting to prevent log injection.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Zookeeper
Zookeeper