Apache ZooKeeper authorization bypass found in deleteContainer path
Apache patched four ZooKeeper flaws, including critical authorization bypass CVE-2026-79993, where the deleteContainer path skips both session and DELETE ACL checks. Fixes shipped in ZooKeeper 3.8.7 and 3.9.6; versions 3.8.0–3.8.6 and 3.9.0–3.9.5 are affected.
- CVE-2026-79993: deleteContainer skips session and DELETE ACL checks
- No credentials needed — only access to the client port 2181
- ZooKeeper 3.8.0–3.8.6 and 3.9.0–3.9.5 affected; fixed in 3.8.7 and 3.9.6
- No active exploitation or public exploit code at disclosure
Read next
Security