Improper validation of certificate with host mismatch in Apache ZooKeeper - CVE-2026-59969
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote user to join quorum traffic and participate in leader election and replication flows.
The vulnerability exists due to improper validation of certificate hostnames in the Java SSLSocket quorum path when processing a CA-trusted peer certificate whose SAN does not match the connected host in a FIPS-mode deployment. A remote user can present such a peer certificate to join quorum traffic and participate in leader election and replication flows.