DEV Community

StarkMan
StarkMan

Posted on

Cluster State Tampering: The Operational Risk of Unauthenticated Znode Deletion

Cluster State Tampering: The Operational Risk of Unauthenticated Znode Deletion

State is the asset

In ZooKeeper the tree of znodes is the source of truth for many systems. An operation that removes nodes without authorization removes that truth.

The deletion path

CVE-2026-79993 bypasses two controls. Apache notes that the deleteContainer request path completely skips both the session check and the DELETE ACL check. An unauthenticated attacker on the client port can therefore delete empty persistent znodes using raw opcodes.

From deletion to disruption

Deleting coordination nodes can interrupt leader election, dissolve membership registrations or drop shared configuration. Systems that wait on those znodes may hang, retry endlessly or fail over incorrectly. The blast radius reaches every service that trusts the cluster.

Compounding factors

CVE-2026-59739 discloses restricted znode names, which helps an attacker target the right nodes. CVE-2026-84439 masks the activity in audit logs. CVE-2026-59969 can admit a rogue quorum member in FIPS mode.

Versions and remediation

Versions 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5 are affected. Upgrade to 3.8.7 or 3.9.6, and restrict port 2181 until the update lands.

References

Top comments (0)