news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans Apache Zookeeper (16 septembre 2026)

MediumCVSS 5.3
Summary

Multiple vulnerabilities have been discovered in Apache Zookeeper, allowing attackers to compromise data confidentiality, integrity, and bypass security policies. Users of Zookeeper versions 3.8.x (prior to 3.8.7) and 3.9.x (prior to 3.9.6) are at risk. The CERT-FR is urging users to apply the provided security updates immediately.

Multiple vulnerabilities have been identified within Apache Zookeeper, presenting significant security risks to its users. These flaws enable an attacker to potentially compromise data confidentiality and integrity, as well as circumvent existing security policies. The CERT-FR is highlighting the need for immediate action to address these issues.

Specifically, Zookeeper versions 3.8.x (prior to 3.8.7) and 3.9.x (prior to 3.9.6) are affected. The CERT-FR recommends consulting the security bulletin provided by Apache Zookeeper for detailed information and available patches.

Relevant CVE identifiers include CVE-2026-59739, CVE-2026-59969, CVE-2026-79993, CVE-2026-84439 and CVE-2026-84501. Users should refer to the security bulletin for the most up-to-date information and instructions on how to apply the necessary security updates.

Read the full article at CERT-FR