Information Disclosure Vulnerability in Apache ZooKeeper by The Apache Software Foundation
CVE-2026-59739

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-59739?

An information disclosure vulnerability exists in Apache ZooKeeper due to a missing Access Control List (ACL) check during the SetWatches reconnect replay. This flaw allows attackers to discover ACL-restricted paths by registering watches on non-existent paths and reconnecting after those paths are created with restricted ACLs. Although the actual data of a znode remains secure, the vulnerability exposes the paths themselves, which may contain sensitive information like usernames or login IDs. It is critical for users to upgrade to versions 3.9.6 or 3.8.7 to mitigate this risk effectively.

Affected Version(s)

Apache ZooKeeper 3.9.0 <= 3.9.5

Apache ZooKeeper 3.8.0 <= 3.8.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NGUYEN HONG QUAN <hongquanvp11@gmail.com>
n0mi1k <nomilksec@gmail.com>
.