Information Disclosure Vulnerability in Apache ZooKeeper by The Apache Software Foundation
CVE-2026-59739
Currently unrated
What is CVE-2026-59739?
An information disclosure vulnerability exists in Apache ZooKeeper due to a missing Access Control List (ACL) check during the SetWatches reconnect replay. This flaw allows attackers to discover ACL-restricted paths by registering watches on non-existent paths and reconnecting after those paths are created with restricted ACLs. Although the actual data of a znode remains secure, the vulnerability exposes the paths themselves, which may contain sensitive information like usernames or login IDs. It is critical for users to upgrade to versions 3.9.6 or 3.8.7 to mitigate this risk effectively.
Affected Version(s)
Apache ZooKeeper 3.9.0 <= 3.9.5
Apache ZooKeeper 3.8.0 <= 3.8.6