CVE-2026-59739: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
CVE-2026-59739: Apache ZooKeeper missing ACL check in SetWatches reconnect replay lets attackers discover ACL-restricted znode paths.
Apache ZooKeeper versions 3.8.0-3.8.6 and 3.9.0-3.9.5 contain a critical information disclosure (CVE-2026-59739) caused by a missing ACL check during SetWatches reconnect replay. An attacker can register exists-watches on non-existent paths and reconnect after those paths are created, revealing the existence of ACL-restricted paths. The issue is fixed in patched releases.
- Affects ZooKeeper 3.8.0-3.8.6 and 3.9.0-3.9.5
- Missing ACL check during SetWatches reconnect replay
- Allows discovery of ACL-restricted paths via exists-watches side channel
- Rated critical by the project
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-59739 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by Andor Molnar on Sep 15 Severity: critical Affected versions: - Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5 - Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6 Description: Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting after the paths are created...
This source does not provide full text. Read it at seclists.org.