ZeroHour
oss-securitypublished ()ingested

CVE-2026-84501: Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider

mediumVulnerabilityimportance 30CVE-2026-84501
AI summary · glm-5.3

Unauthenticated attackers can forge Apache ZooKeeper operational log lines via newline injection in crafted ensemble authentication requests.

CVE-2026-84501 (moderate severity) affects Apache ZooKeeper 3.9.0-3.9.5 and 3.8.0-3.8.6. An unauthenticated attacker can inject arbitrary fake log lines into the operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters. The forged entries could mislead operators or corrupt log-based monitoring and forensics.

  • Rated moderate; affects ZooKeeper 3.8.0-3.8.6 and 3.9.0-3.9.5
  • Unauthenticated attacker injects fake log lines via newline characters
  • Vector is crafted add_auth("ensemble", ...) request

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-84501

NVD description · AI analysis pending
Full article

Posted by Andor Molnar on Sep 15 Severity: moderate Affected versions: - Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5 - Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6 Description: An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't...

This source does not provide full text. Read it at seclists.org.