DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

Apache ZooKeeper Authorization Bypass: How deleteContainer Skips Session and ACL Checks

Apache ZooKeeper Authorization Bypass: How deleteContainer Skips Session and ACL Checks

Overview

Apache ZooKeeper, the coordination service that keeps distributed clusters in sync, received patches in September 2026 for four flaws. The most serious is an authorization bypass tracked as CVE-2026-79993. Apache rates it critical, and the project shipped fixes in ZooKeeper 3.8.7 and 3.9.6.

The flaw

The defect lives in an undocumented protocol handler. Apache's advisory is blunt about the gap: "the deleteContainer request path completely skips both the session check and the DELETE ACL check." Two independent guards that normally protect destructive operations are simply absent on that path.

Exploitation conditions

An attacker does not need credentials. Anyone who can reach the ZooKeeper client port, 2181 by default, can send raw opcode requests. The operation targets empty persistent znodes. Because the handler never validates the session or the ACL, the request is processed as if it came from a trusted administrator.

Impact

Successful exploitation lets an unauthenticated party delete critical nodes. In a coordination service, removed znodes can break leader election, membership tracking or configuration distribution. Downstream systems such as Apache Hadoop and Apache Kafka that depend on ZooKeeper for cluster state may then stall or split.

Affected products and scope

ZooKeeper versions 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5 are affected. Apache confirmed no active in-the-wild exploitation and no public exploit code at disclosure time.

Remediation

Upgrade clusters to 3.8.7 or 3.9.6 from the official Apache ZooKeeper releases. Where upgrades must wait, restrict network access to port 2181 with trusted internal firewalls. Review audit logs for unauthorized deletion commands.

References

Top comments (0)