https://seclists.org/oss-sec/2026/q3/788: CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
Published Sep 15, 2026
·Updated
Affected Software
2 affected components
Apache Zookeeper>=3.9.0<=3.9.5
Apache Zookeeper>=3.8.0<=3.8.6
Frequently Asked Questions
1
Are ZooKeeper deployments affected if audit logging is not enabled?
The described injection occurs when audit logging is enabled with zookeeper.audit.enable=true. The provided information does not identify an impact when audit logging is disabled.
2
What access does an attacker need to manipulate audit records?
One attack path is an unauthenticated digest authentication request containing tab characters in the username. Another requires a client that can call setACL and can supply a digest ACL ID containing tab characters.
3
What audit evidence can be falsified through this issue?
Injected tab characters can create forged key=value fields in tab-separated audit records. This can spoof values such as result=success, operation=delete, and znode=/forged, corrupting the apparent details of an event.