PatchSiren cyber security CVE debrief
CVE-2026-84501 Apache Software Foundation CVE debrief
Apache ZooKeeper is vulnerable to log injection attacks. An unauthenticated attacker can inject fake log lines into ZooKeeper's operational log by sending a crafted add_auth request containing newline characters. This issue affects ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6. Users are recommended to upgrade to version 3.8.7 or 3.9.6.
- Vendor
- Apache Software Foundation
- Product
- Apache ZooKeeper
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-18
Who should care
System administrators and security teams responsible for Apache ZooKeeper installations should assess exposure and upgrade to patched versions. They should also review and monitor ZooKeeper logs for suspicious activity and implement additional security measures to prevent unauthorized access. Security teams should verify log entries for suspicious activity and review system logs.
Why it matters
Apache ZooKeeper is vulnerable to log injection attacks, which could allow an attacker to forge log entries. System administrators and security teams should assess exposure, upgrade to patched versions, and monitor logs for suspicious activity.
- Potential log injection attacks may require log review and monitoring
- Upgrade to patched versions is necessary to prevent the vulnerability
- Verification of ZooKeeper logs for suspicious activity is recommended
Technical summary
An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth request containing newline characters. This issue affects Apache ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6. The vulnerability allows an attacker to forge log entries that are visually indistinguishable from genuine ZooKeeper log output. Users are recommended to upgrade to version 3.8.7 or 3.9.6 to prevent log injection attacks. Defenders should review system logs for suspicious activity.
Defensive priority
Upgrade to patched versions 3.8.7 or 3.9.6 to prevent log injection attacks.
Recommended defensive actions
- Upgrade to version 3.8.7 or 3.9.6
- Review and monitor ZooKeeper logs for suspicious activity
- Implement additional security measures to prevent unauthorized access
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected versions, and recommended upgrades. Apache ZooKeeper's log injection vulnerability allows an unauthenticated attacker to inject fake log lines by sending a crafted add_auth request containing newline characters. This issue affects ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6. Users are recommended to upgrade to version 3.8.7 or 3.9.6. Defenders should verify log entries for suspicious activity and review system logs.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84501 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84501
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84501 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84501
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/ohby1g6zjt72p0w79rhbr41nczzvr33y
[email protected] - Mailing List, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.