CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
Published Sep 15, 2026
·Updated
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ZooKeeperto a version that resolves this vulnerability.Fixed in 3.9.6 - Upgrade
Upgrade
Apache ZooKeeperto a version that resolves this vulnerability.Fixed in 3.8.7 - Configuration
Disable audit logging by setting zookeeper.audit.enable=false to prevent forged fields from being written to zookeeper_audit.log.
Apache ZooKeeper zookeeper.audit.enable = false
Event History
Sep 16, 2026
CVE Published
via MITRE·09:27 AM
Data Sourced
via MITRE·09:27 AM
DescriptionWeakness