PT-2026-93418 · Apache · Zookeeper+1
CVE-2026-84501
·
Published
2026-09-16
·
Updated
2026-09-29
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ZooKeeper versions 3.8.0 through 3.8.6
Apache ZooKeeper versions 3.9.0 through 3.9.5
Description
An unauthenticated attacker can inject arbitrary fake log lines into the operational log by sending a crafted
add auth("ensemble", ...) request containing newline characters ( ). When the ensemble name does not match, the EnsembleAuthenticationProvider.handleAuthentication() function logs the raw, unsanitized name via LOG.warn(). Since the SLF4J {} placeholder preserves embedded newlines, an attacker can forge complete log entries including arbitrary timestamps, log levels, class names, and messages that are visually indistinguishable from genuine output.Recommendations
Upgrade versions 3.8.0 through 3.8.6 to version 3.8.7.
Upgrade versions 3.9.0 through 3.9.5 to version 3.9.6.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Zookeeper
Zookeeper