ZooKeeper Replication Vulnerability in CentralDogma Server by LINE Corporation
CVE-2026-11746
9.4CRITICAL
What is CVE-2026-11746?
A significant security issue has been identified in versions of CentralDogma Server prior to 0.84.0 that enables ZooKeeper replication without proper credential management. If the replication.secret is not set, the server defaults to a hard-coded secret, known publicly. This configuration flaw can be exploited by attackers with network access, providing them the ability to read sensitive replication logs or even join the quorum, which allows for executing arbitrary commands across the cluster. Proper configuration is critical to ensure security and prevent unauthorized access to the server.
Affected Version(s)
Central Dogma 0.84.0
