PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84501 Apache Software Foundation CVE debrief

Apache ZooKeeper is vulnerable to log injection attacks. An unauthenticated attacker can inject fake log lines into ZooKeeper's operational log by sending a crafted add_auth request containing newline characters. This issue affects ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6. Users are recommended to upgrade to version 3.8.7 or 3.9.6.

Vendor
Apache Software Foundation
Product
Apache ZooKeeper
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-18
Advisory published
2026-09-16
Advisory updated
2026-09-18

Who should care

System administrators and security teams responsible for Apache ZooKeeper installations should assess exposure and upgrade to patched versions. They should also review and monitor ZooKeeper logs for suspicious activity and implement additional security measures to prevent unauthorized access. Security teams should verify log entries for suspicious activity and review system logs.

Why it matters

Apache ZooKeeper is vulnerable to log injection attacks, which could allow an attacker to forge log entries. System administrators and security teams should assess exposure, upgrade to patched versions, and monitor logs for suspicious activity.

  • Potential log injection attacks may require log review and monitoring
  • Upgrade to patched versions is necessary to prevent the vulnerability
  • Verification of ZooKeeper logs for suspicious activity is recommended

Technical summary

An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth request containing newline characters. This issue affects Apache ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6. The vulnerability allows an attacker to forge log entries that are visually indistinguishable from genuine ZooKeeper log output. Users are recommended to upgrade to version 3.8.7 or 3.9.6 to prevent log injection attacks. Defenders should review system logs for suspicious activity.

Defensive priority

Upgrade to patched versions 3.8.7 or 3.9.6 to prevent log injection attacks.

Recommended defensive actions

  • Upgrade to version 3.8.7 or 3.9.6
  • Review and monitor ZooKeeper logs for suspicious activity
  • Implement additional security measures to prevent unauthorized access
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and recommended upgrades. Apache ZooKeeper's log injection vulnerability allows an unauthenticated attacker to inject fake log lines by sending a crafted add_auth request containing newline characters. This issue affects ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6. Users are recommended to upgrade to version 3.8.7 or 3.9.6. Defenders should verify log entries for suspicious activity and review system logs.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84501 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84501

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84501 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84501

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.