chiprook
← Security
SecurityOctober 4, 2026, 21:40

Apache ZooKeeper authorization bypass found in deleteContainer path

Apache patched four ZooKeeper flaws, including critical authorization bypass CVE-2026-79993, where the deleteContainer path skips both session and DELETE ACL checks. Fixes shipped in ZooKeeper 3.8.7 and 3.9.6; versions 3.8.0–3.8.6 and 3.9.0–3.9.5 are affected.

Apache ZooKeeper authorization bypass found in deleteContainer path
#Apache#ZooKeeper
Read next
Security

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization

Security

vm2 CVE-2026-100721: path allowlist bypassed by prefix match

Security

MCPVault path filters bypassed: CVE-2026-57441 and CVE-2026-57442

Security

SiYuan below v3.7.4 has authorization flaw rated 8.7