Apache ZooKeeper Authorization Bypass: How deleteContainer Skips Session and ACL Checks
Overview
Apache ZooKeeper, the coordination service that keeps distributed clusters in sync, received patches in September 2026 for four flaws. The most serious is an authorization bypass tracked as CVE-2026-79993. Apache rates it critical, and the project shipped fixes in ZooKeeper 3.8.7 and 3.9.6.
The flaw
The defect lives in an undocumented protocol handler. Apache's advisory is blunt about the gap: "the deleteContainer request path completely skips both the session check and the DELETE ACL check." Two independent guards that normally protect destructive operations are simply absent on that path.
Exploitation conditions
An attacker does not need credentials. Anyone who can reach the ZooKeeper client port, 2181 by default, can send raw opcode requests. The operation targets empty persistent znodes. Because the handler never validates the session or the ACL, the request is processed as if it came from a trusted administrator.
Impact
Successful exploitation lets an unauthenticated party delete critical nodes. In a coordination service, removed znodes can break leader election, membership tracking or configuration distribution. Downstream systems such as Apache Hadoop and Apache Kafka that depend on ZooKeeper for cluster state may then stall or split.
Affected products and scope
ZooKeeper versions 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5 are affected. Apache confirmed no active in-the-wild exploitation and no public exploit code at disclosure time.
Remediation
Upgrade clusters to 3.8.7 or 3.9.6 from the official Apache ZooKeeper releases. Where upgrades must wait, restrict network access to port 2181 with trusted internal firewalls. Review audit logs for unauthorized deletion commands.
References
- Critical Apache ZooKeeper Vulnerabilities Patched in Update (SecurityOnline): https://securityonline.info/apache-zookeeper-vulnerabilities-fixed/
- Apache ZooKeeper security advisories: https://zookeeper.apache.org/security.html
Top comments (0)