{"id":11230,"date":"2026-03-10T10:03:49","date_gmt":"2026-03-10T10:03:49","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/10\/apache-zookeeper-vulnerability-allow-attackers-to-access-sensitive-data\/"},"modified":"2026-03-10T10:03:49","modified_gmt":"2026-03-10T10:03:49","slug":"apache-zookeeper-vulnerability-allow-attackers-to-access-sensitive-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/10\/apache-zookeeper-vulnerability-allow-attackers-to-access-sensitive-data\/","title":{"rendered":"Apache ZooKeeper Vulnerability Allow Attackers to Access Sensitive Data"},"content":{"rendered":"<p>    Apache ZooKeeper Vulnerability Allow Attackers to Access Sensitive Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Two \u201cImportant\u201d severity vulnerabilities have been disclosed in Apache ZooKeeper, a widely used service for configuration management and naming in distributed applications, making timely security updates critical.<\/p>\n<p>These newly discovered flaws could allow attackers to access sensitive configuration data or <a href=\"https:\/\/cybersecuritynews.com\/ingressnightmare\/\" target=\"_blank\" rel=\"noreferrer noopener\">bypass hostname verification<\/a> to impersonate trusted servers. Both vulnerabilities affect ZooKeeper versions 3.8. x and 3.9. x branches.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-apache-zookeeper-vulnerability\"><strong>Apache ZooKeeper Vulnerability<\/strong><\/h2>\n<p>The first vulnerability, tracked as CVE-2026-24308, involves the disclosure of sensitive information.<\/p>\n<p>Discovered by researcher Youlong Chen, this flaw occurs due to the <a href=\"https:\/\/cybersecuritynews.com\/libreoffice-vulnerabilities-arbitrary-file\/\" target=\"_blank\" rel=\"noreferrer noopener\">improper handling of configuration values<\/a> in the\u00a0ZKConfig\u00a0component.<\/p>\n<p>When a client connects, sensitive configuration data is accidentally printed to the client\u2019s log file at the default INFO logging level.<\/p>\n<p>This means any unauthorized user or attacker with access to the system\u2019s log files could quietly <a href=\"https:\/\/cybersecuritynews.com\/apache-seatunnel-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">steal sensitive production data <\/a>without triggering alarms.<\/p>\n<p>The second issue, tracked as CVE-2026-24281 (and internally as ZOOKEEPER-4986), is a hostname verification bypass discovered by Nikita Markevich.<\/p>\n<p>In the\u00a0ZKTrustManager\u00a0component, if IP Subject Alternative Name (SAN) validation fails, the system automatically <a href=\"https:\/\/cybersecuritynews.com\/mystrodx-leveraging-dns-and-icmp\/\" target=\"_blank\" rel=\"noreferrer noopener\">falls back to a reverse DNS (PTR) lookup.<\/a><\/p>\n<p>An attacker who controls or spoofs PTR records can exploit this behavior to impersonate valid ZooKeeper servers or clients.<\/p>\n<p>While the attacker must still present a certificate trusted by\u00a0ZKTrustManager, which makes this harder to exploit, a successful attack completely undermines the system\u2019s trust model.<\/p>\n<p>To protect infrastructure from these threats, <a href=\"https:\/\/zookeeper.apache.org\/security.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Apache highly recommends that administrators<\/a> immediately upgrade their ZooKeeper installations to the patched versions.<\/p>\n<p>The official fixes are available in\u00a0Apache ZooKeeper versions 3.8.6\u00a0and\u00a03.9.5. Applying these updates resolves the logging exposure flaw, ensuring that\u00a0ZKConfig\u00a0no longer leaks sensitive values into local files.<\/p>\n<p>Furthermore, the updates fix the hostname bypass issue by introducing a new configuration option that turns off reverse DNS lookups for both the client and quorum protocols.<\/p>\n<p>In addition to patching, security teams should actively review their logging environments to ensure no historically sensitive data remains exposed in older, archived log files.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apache-zookeeper-vulnerability\/\">Apache ZooKeeper Vulnerability Allow Attackers to Access Sensitive Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apache-zookeeper-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apache ZooKeeper Vulnerability Allow Attackers to Access Sensitive Data Two \u201cImportant\u201d severity vulnerabilities have been disclosed in Apache ZooKeeper, a widely used service for configuration management and naming in distributed applications, making timely security updates critical. These newly discovered flaws could allow attackers to access sensitive configuration data or bypass hostname verification to impersonate trusted [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[803,129,63,648],"tags":[130],"class_list":["post-11230","post","type-post","status-publish","format-standard","hentry","category-apache","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11230"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11230"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11230\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}