CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
Apache ZooKeeper audit logs are vulnerable to arbitrary field injection by unauthenticated attackers via tab characters in digest auth requests.
CVE-2026-84439 (important severity) affects Apache ZooKeeper 3.9.0-3.9.5 and 3.8.0-3.8.6 when audit logging is enabled (zookeeper.audit.enable=true). An unauthenticated attacker can inject arbitrary fields into the audit log by sending a digest authentication request with embedded tab characters, undermining audit trail integrity and potentially enabling log-analysis evasion or spoofing.
- Rated important; affects ZooKeeper 3.8.0-3.8.6 and 3.9.0-3.9.5
- Requires audit logging enabled (zookeeper.audit.enable=true)
- Unauthenticated injection via tab characters in digest auth requests
- Compromises audit log integrity used for compliance and forensics
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84439 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by Andor Molnar on Sep 15 Severity: important Affected versions: - Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5 - Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6 Description: When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the...
This source does not provide full text. Read it at seclists.org.