ZeroHour
oss-securitypublished ()ingested

CVE-2026-59739: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay

AI summary · glm-5.3

CVE-2026-59739: Apache ZooKeeper missing ACL check in SetWatches reconnect replay lets attackers discover ACL-restricted znode paths.

Apache ZooKeeper versions 3.8.0-3.8.6 and 3.9.0-3.9.5 contain a critical information disclosure (CVE-2026-59739) caused by a missing ACL check during SetWatches reconnect replay. An attacker can register exists-watches on non-existent paths and reconnect after those paths are created, revealing the existence of ACL-restricted paths. The issue is fixed in patched releases.

  • Affects ZooKeeper 3.8.0-3.8.6 and 3.9.0-3.9.5
  • Missing ACL check during SetWatches reconnect replay
  • Allows discovery of ACL-restricted paths via exists-watches side channel
  • Rated critical by the project

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-59739

NVD description · AI analysis pending
Full article

Posted by Andor Molnar on Sep 15 Severity: critical Affected versions: - Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5 - Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6 Description: Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting after the paths are created...

This source does not provide full text. Read it at seclists.org.