CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode
The deleteContainer opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the znode or its parent. This opcode is considered internal-only and the official client doesn't have API for it, but a client that can open a plain TCP session on the ZooKeeper client port (2181 by default) - with NO authentication and NO ACL permissions - can delete any empty persistent znode (including regular persistent nodes, container nodes, and TTL nodes) by issuing the raw protocol OpCode deleteContainer (20). The deleteContainer request path completely skips both the session check and the DELETE ACL check that are enforced by the regular delete (OpCode 2) path. This is an authorization bypass / ACL enforcement bug.
This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5, from 3.8.0 through 3.8.6.
Users are recommended to upgrade to version 3.9.6 or 3.8.7, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ZooKeeperto a version that resolves this vulnerability.Fixed in 3.9.6 - Upgrade
Upgrade
Apache ZooKeeperto a version that resolves this vulnerability.Fixed in 3.8.7
Event History
Frequently Asked Questions
Who can exploit this issue?
Any client that can establish a plain TCP connection to the ZooKeeper client port, which is 2181 by default, can exploit it. Authentication and DELETE ACL permission are not required.
What conditions are required for a znode to be deleted?
The target must be an empty persistent znode. This includes regular persistent nodes, container nodes, and TTL nodes.
Are systems using ACLs protected from this attack?
No. The affected deleteContainer request path skips both the session check and the DELETE ACL check, so ACL restrictions on the target znode and its parent do not prevent deletion.
Which versions should be upgraded?
Apache ZooKeeper 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6 are affected. Upgrade to 3.9.6 or 3.8.7.
What can be done if an upgrade cannot be applied immediately?
Restrict network access to the ZooKeeper client port so untrusted clients cannot establish TCP sessions to it. The provided information does not describe another configuration-based mitigation.