Improper Output Neutralization for Logs in Apache ZooKeeper - CVE-2026-84439

 

Improper Output Neutralization for Logs in Apache ZooKeeper - CVE-2026-84439

Published: September 16, 2026


Vulnerability identifier: #VU150213
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84439
CWE-ID: CWE-117
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to tamper with audit log records.

The vulnerability exists due to improper output neutralization in audit log serialization when processing digest authentication requests or setACL operations containing tab characters. A remote user can submit a crafted digest username or ACL identifier to inject forged key-value fields into the audit log.

The issue is exploitable only when audit logging is enabled.


Affected software

Apache ZooKeeper

How to mitigate CVE-2026-84439

Install security update from vendor's website.

Apache ZooKeeper - addressed in versions 3.8.7, 3.9.6

External References

Related Security Bulletins