https://seclists.org/oss-sec/2026/q3/785: CVE-2026-59739: Apache ZooKeeper: Information disclosuvia SetWatches connect play
Published Sep 15, 2026
·Updated
Affected Software
2 affected components
Apache Zookeeper>=3.9.0<=3.9.5
Apache Zookeeper>=3.8.0<=3.8.6
Frequently Asked Questions
1
What must an attacker do to disclose restricted znode paths?
The attacker must first register exists-watches on paths that do not exist. After those paths are created with restricted ACLs, the attacker reconnects so ZooKeeper replays the watches through SetWatches or SetWatches2.
2
What information is exposed?
The issue exposes the znode path only, not the znode's data. Paths may still contain sensitive information such as user names or login IDs.
3
Which deployments are affected?
Apache ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6 are affected. The issue involves reconnect watch replay and missing ACL enforcement in that replay path.
4
What should operators do?
Upgrade ZooKeeper 3.9 installations to 3.9.6 or 3.8 installations to 3.8.7. These versions fix the issue.