Description
Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting after the paths are created with restricted ACLs. Issue is caused by incomplete fix for CVE-2024-23944 (ZOOKEEPER-4799). The fix added ACL checking to WatchManager.triggerWatch(). However, DataTree.setWatches() — the SetWatches/SetWatches2 reconnect replay handler — still calls watcher.process(event) with null ACL, bypassing the check entirely. It's important to note that only the path is exposed by this vulnerability, not the data of znode, but since znode path can contain sensitive information like user name or login ID, this issue is potentially critical.

Users are recommended to upgrade to version 3.9.6, 3.8.7 which fixes the issue.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure – sensitive path exposure
Action: Patch Now
AI Analysis

Impact

There is an information‑disclosure flaw in Apache ZooKeeper caused by a missing ACL check during the reconnect replay of SetWatches requests. When an attacker registers an exists‑watch on a path that does not yet exist, and then reconnects after the path has been created with restrictive ACLs, ZooKeeper will trigger the watch with a null ACL, bypassing the access control check in WatchManager.triggerWatch(). The result is that the attacker learns the pathname of a znode that is normally ACL‑protected. While the flaw does not reveal the znode’s payload, the path itself may contain sensitive identifiers such as usernames or login IDs, making this a potentially critical vulnerability. The weakness is a classic example of CWE‑862: Missing Authorization, and also reflects CWE‑425: Incomplete Verification of Permissions.

Affected Systems

The flaw applies to all ZooKeeper 3.9.x and 3.8.x releases prior to Apache ZooKeeper 3.9.6 and 3.8.7, which lack the proper ACL verification in DataTree.setWatches(). The vendor responsible is the Apache Software Foundation, and any deployment that utilizes ZooKeeper ensembles communicating over an untrusted network is affected.

Risk and Exploitability

With a CVSS score of 7.5, this vulnerability is of high severity. The EPSS score is less than 1 %, indicating a low probability of exploitation at the time of analysis, and the issue is not listed in the CISA KEV catalog. Attackers would need remote network access to the ZooKeeper service and the ability to issue SetWatches requests; this requirement is inferred from the description because the CVE specifically mentions issuing SetWatches requests, but it does not state the exact network conditions. No local privilege escalation or advanced exploitation is required. The risk is mitigated entirely by applying the approved patch, after which the ACL checks are enforced correctly and the path disclosure vector is eliminated.

Generated by OpenCVE AI on September 28, 2026 at 15:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache ZooKeeper 3.9.6 or 3.8.7 or later releases that include the ACL check fix.
  • Configure ZooKeeper to enforce client authentication (e.g., TLS or SASL) so that only verified clients can register watches.
  • Restrict ZooKeeper client access to authorized IP ranges or implement firewall rules to limit connections.

Generated by OpenCVE AI on September 28, 2026 at 15:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-425
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache zookeeper
Vendors & Products Apache
Apache zookeeper

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting after the paths are created with restricted ACLs. Issue is caused by incomplete fix for CVE-2024-23944 (ZOOKEEPER-4799). The fix added ACL checking to WatchManager.triggerWatch(). However, DataTree.setWatches() — the SetWatches/SetWatches2 reconnect replay handler — still calls watcher.process(event) with null ACL, bypassing the check entirely. It's important to note that only the path is exposed by this vulnerability, not the data of znode, but since znode path can contain sensitive information like user name or login ID, this issue is potentially critical. Users are recommended to upgrade to version 3.9.6, 3.8.7 which fixes the issue.
Title Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
Weaknesses CWE-862
References

Subscriptions

Apache Zookeeper
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-17T19:19:17.226Z

Reserved: 2026-07-06T20:46:19.936Z

Link: CVE-2026-59739

cve-icon Vulnrichment

Updated: 2026-09-17T19:19:12.263Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T10:16:51.097

Modified: 2026-09-18T14:37:10.223

Link: CVE-2026-59739

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T09:26:37Z

Links: CVE-2026-59739 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:15:03Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')

  • CWE-862

    Missing Authorization