Improper validation of certificate with host mismatch in Apache ZooKeeper - CVE-2026-59969

 

Improper validation of certificate with host mismatch in Apache ZooKeeper - CVE-2026-59969

Published: September 16, 2026


Vulnerability identifier: #VU150216
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59969
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to join quorum traffic and participate in leader election and replication flows.

The vulnerability exists due to improper validation of certificate hostnames in the Java SSLSocket quorum path when processing a CA-trusted peer certificate whose SAN does not match the connected host in a FIPS-mode deployment. A remote user can present such a peer certificate to join quorum traffic and participate in leader election and replication flows.


Affected software

Apache ZooKeeper

How to mitigate CVE-2026-59969

Install security update from vendor's website.

Apache ZooKeeper - addressed in versions 3.8.7, 3.9.6

External References

Related Security Bulletins