Users are recommended to upgrade to version 3.9.6, 3.8.7 which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache zookeeper |
|
| Vendors & Products |
Apache
Apache zookeeper |
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 16 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting after the paths are created with restricted ACLs. Issue is caused by incomplete fix for CVE-2024-23944 (ZOOKEEPER-4799). The fix added ACL checking to WatchManager.triggerWatch(). However, DataTree.setWatches() — the SetWatches/SetWatches2 reconnect replay handler — still calls watcher.process(event) with null ACL, bypassing the check entirely. It's important to note that only the path is exposed by this vulnerability, not the data of znode, but since znode path can contain sensitive information like user name or login ID, this issue is potentially critical. Users are recommended to upgrade to version 3.9.6, 3.8.7 which fixes the issue. | |
| Title | Apache ZooKeeper: Information disclosure via SetWatches reconnect replay | |
| Weaknesses | CWE-862 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-17T19:19:17.226Z
Reserved: 2026-07-06T20:46:19.936Z
Link: CVE-2026-59739
No data.
Status : Undergoing Analysis
Published: 2026-09-16T10:16:51.097
Modified: 2026-09-17T20:16:53.830
Link: CVE-2026-59739
No data.
OpenCVE Enrichment
Updated: 2026-09-17T20:49:55Z