Log Injection Vulnerability in Apache ZooKeeper Affects Multiple Versions
CVE-2026-84439

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-84439?

A log injection vulnerability in Apache ZooKeeper allows unauthenticated attackers to manipulate audit logs by injecting arbitrary fields through crafted digest authentication requests. This allows attackers to spoof audit results, forge operation types, and corrupt forensic evidence. When audit logging is enabled, attackers may exploit tab characters in usernames to alter the output of zookeeper_audit.log, making it appear as though legitimate operations occurred. This can severely undermine the integrity of audit parsing and incident response mechanisms. Users are advised to upgrade to versions 3.9.6 or 3.8.7 to mitigate this issue.

Affected Version(s)

Apache ZooKeeper 3.9.0 <= 3.9.5

Apache ZooKeeper 3.8.0 <= 3.8.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Youlong Chen Institute of Computing Technology <chenyoulong20g@ict.ac.cn>
.