Impact
There is an information‑disclosure flaw in Apache ZooKeeper caused by a missing ACL check during the reconnect replay of SetWatches requests. When an attacker registers an exists‑watch on a path that does not yet exist, and then reconnects after the path has been created with restrictive ACLs, ZooKeeper will trigger the watch with a null ACL, bypassing the access control check in WatchManager.triggerWatch(). The result is that the attacker learns the pathname of a znode that is normally ACL‑protected. While the flaw does not reveal the znode’s payload, the path itself may contain sensitive identifiers such as usernames or login IDs, making this a potentially critical vulnerability. The weakness is a classic example of CWE‑862: Missing Authorization, and also reflects CWE‑425: Incomplete Verification of Permissions.
Affected Systems
The flaw applies to all ZooKeeper 3.9.x and 3.8.x releases prior to Apache ZooKeeper 3.9.6 and 3.8.7, which lack the proper ACL verification in DataTree.setWatches(). The vendor responsible is the Apache Software Foundation, and any deployment that utilizes ZooKeeper ensembles communicating over an untrusted network is affected.
Risk and Exploitability
With a CVSS score of 7.5, this vulnerability is of high severity. The EPSS score is less than 1 %, indicating a low probability of exploitation at the time of analysis, and the issue is not listed in the CISA KEV catalog. Attackers would need remote network access to the ZooKeeper service and the ability to issue SetWatches requests; this requirement is inferred from the description because the CVE specifically mentions issuing SetWatches requests, but it does not state the exact network conditions. No local privilege escalation or advanced exploitation is required. The risk is mitigated entirely by applying the approved patch, after which the ACL checks are enforced correctly and the path disclosure vector is eliminated.
OpenCVE Enrichment