PT-2026-93417 · Apache · Zookeeper+1

CVE-2026-84439

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache ZooKeeper versions 3.9.0 through 3.9.5 Apache ZooKeeper versions 3.8.0 through 3.8.6
Description Log injection occurs when audit logging is enabled via zookeeper.audit.enable=true. An unauthenticated attacker can inject arbitrary fields into the audit log by sending a digest authentication request containing tab characters (t) in the username. Additionally, a client capable of calling the setACL() function can inject forged key-value fields into the zookeeper audit.log because the server fails to escape tab characters when serializing digest ACL ids into the acl field. Since the audit log uses a tab-separated key=value format, these injected tabs are interpreted as legitimate separators, allowing attackers to spoof results (e.g., result=success), forge operation types (e.g., operation=delete), and corrupt forensic evidence, which compromises downstream audit parsing and incident response.
Recommendations Upgrade Apache ZooKeeper versions 3.9.0 through 3.9.5 to version 3.9.6. Upgrade Apache ZooKeeper versions 3.8.0 through 3.8.6 to version 3.8.7. As a temporary mitigation, consider disabling the zookeeper.audit.enable setting to prevent log injection.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ZOOKEEPER-2026-84439
CVE-2026-84439

Affected Products

Apache Zookeeper
Zookeeper