Improper Output Neutralization for Logs in Apache ZooKeeper - CVE-2026-84439
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote user to tamper with audit log records.
The vulnerability exists due to improper output neutralization in audit log serialization when processing digest authentication requests or setACL operations containing tab characters. A remote user can submit a crafted digest username or ACL identifier to inject forged key-value fields into the audit log.
The issue is exploitable only when audit logging is enabled.