ZooKeeper Information Disclosure: Existence Watches Leak Restricted Znode Names
Summary
Among the four Apache ZooKeeper flaws fixed in September 2026, CVE-2026-59739 exposes information rather than allowing direct deletion. The bug sits in the watch management subsystem and resurfaces during client reconnection.
Background
An earlier patch intended to close a watch-management weakness. That fix proved incomplete. The incomplete patch is the root cause of the current issue.
Mechanism
Attackers register existence watches on paths that do not exist yet. When a client reconnects, the service returns watch-related data that reveals restricted znode names. The node payload itself stays protected, which is why this is an information disclosure and not a data breach of stored values.
What leaks and why it matters
Exposed paths frequently contain sensitive usernames and internal identifiers. Naming conventions in a ZooKeeper tree can reveal service topology, environment names or account references. That reconnaissance shortens the path to follow-on attacks, including the unauthenticated deletion path described in CVE-2026-79993.
Scope
Affected releases are ZooKeeper 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5. Apache reported no confirmed exploitation and no public proof-of-concept.
Mitigation
Move to 3.8.7 or 3.9.6. Until then, limit who can reach port 2181 and treat znode naming as sensitive metadata. Operators should also watch for unusual watch registration against non-existent paths.
References
- Critical Apache ZooKeeper Vulnerabilities Patched in Update (SecurityOnline): https://securityonline.info/apache-zookeeper-vulnerabilities-fixed/
- Apache ZooKeeper security advisories: https://zookeeper.apache.org/security.html
Top comments (0)