CVE-2026-24308

HIGH

Apache ZooKeeper 3.8.5/3.9.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue.

Scores

CVSS v3 7.5
EPSS 0.0118
EPSS Percentile 64.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-117 CWE-532
Status published
Products (4)
apache/zookeeper 3.8.0 - 3.8.6
Apache Software Foundation/Apache ZooKeeper 3.8.0 - 3.8.5
Apache Software Foundation/Apache ZooKeeper 3.9.0 - 3.9.4
org.apache.zookeeper/zookeeper 3.9.0 - 3.9.5Maven
Published Mar 07, 2026
Tracked Since Mar 07, 2026