https://seclists.org/oss-sec/2026/q3/787: CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode
Affected Software
Frequently Asked Questions
Who can exploit this issue?
Any client able to open a plain TCP connection to the ZooKeeper client port, which is 2181 by default, can issue the raw deleteContainer opcode. Authentication and ACL permissions are not required.
Are default or ACL-protected deployments affected?
Yes. The vulnerable request path bypasses both the session check and the DELETE ACL check, so ACL restrictions on the target znode or its parent do not prevent deletion.
What data can be deleted through this flaw?
An attacker can delete any empty persistent znode, including regular persistent nodes, container nodes, and TTL nodes. The target must be empty.
How can I determine whether a ZooKeeper instance is affected?
Instances using ZooKeeper versions 3.9.0 through 3.9.5 or 3.8.0 through 3.8.6 are affected. Exposure also requires that an attacker can reach the ZooKeeper client port.
What is the remediation?
Upgrade ZooKeeper 3.9 deployments to 3.9.6 or 3.8 deployments to 3.8.7. If an upgrade cannot be performed immediately, restrict network access to the ZooKeeper client port to trusted clients.