Authorization Bypass in Apache ZooKeeper Affecting Multiple Versions
CVE-2026-79993

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-79993?

The vulnerability arises from an issue in the deleteContainer opcode (0x14/20) in Apache ZooKeeper. This opcode allows any authenticated client to delete specific znodes in the data tree without respecting ACL permissions, effectively bypassing authorization controls. In this case, the opcode is treated as internal-only, but the potential for exploitation exists via a plain TCP session on the ZooKeeper client port (default 2181), enabling unauthorized deletion of any empty persistent znode. The affected versions range from 3.9.0 to 3.9.5 and from 3.8.0 to 3.8.6. Users should upgrade to versions 3.9.6 or 3.8.7 to mitigate this vulnerability.

Affected Version(s)

Apache ZooKeeper 3.9.0 <= 3.9.5

Apache ZooKeeper 3.8.0 <= 3.8.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

K <sec-reports@outlook.com>
z f <tinkerzf@gmail.com>
布豪 <1958304602@qq.com>
.