CVE-2026-59739 in ZooKeeper: existence watches leak restricted znode names
Apache ZooKeeper has an information disclosure flaw, CVE-2026-59739: existence watches on non-existent paths reveal restricted znode names when a client reconnects. Versions 3.8.0–3.8.6 and 3.9.0–3.9.5 are affected; fixes are in 3.8.7 and 3.9.6. No exploitation has been confirmed.
- CVE-2026-59739 is an information disclosure, not data deletion
- Affected: ZooKeeper 3.8.0–3.8.6 and 3.9.0–3.9.5
- Fixed in versions 3.8.7 and 3.9.6
- Leaked path names aid follow-on attacks, including CVE-2026-79993
Read next
Security