CVE-2026-24308Disclosure(apache / zookeeper)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache zookeeper systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532CWE-117

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zookeeper

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • Peaked 4d ago at 4 mentions (2026-03-09); latest day: 2
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
zookeeper

Deep dive

Activity timeline12 mentions / 6d
01234Mentions · 2026-03-07: 3Mentions · 2026-03-09: 4Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Mentions · 2026-04-03: 2Patch / Workaround · 2026-03-09: 2Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-04-03: 2Technical Details · 2026-03-07: 3Technical Details · 2026-03-09: 4Technical Details · 2026-03-12: 1Technical Details · 2026-03-16: 103-0703-0903-1103-1203-1604-03
Signal classification2 categories
Disclosure
758.3%
Patch
541.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-073
Disclosure3
2026-03-094
Disclosure2Patch2
2026-03-111
Patch1
2026-03-121
Disclosure1
2026-03-161
Disclosure1
2026-04-032
Patch2
Full discourse12 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-24281: Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager https://www.openwall.com/lists/oss-security/2026/03/07/4 CVE-2026-24308: Apache ZooKeeper: Sensitive information disclosure in client configuration handling https://www.openwall.com/lists/oss-security/2026/03/07/5

    Post summary

    Two new CVEs affecting Apache ZooKeeper have been disclosed, outlining a hostname verification bypass and a sensitive information disclosure. The provided text does not include PoC, exploit, or patch details.

    00041326
    4.4K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    Dataproc update on April 2, 2026 https://docs.cloud.google.com/dataproc/docs/release-notes#April_02_2026 #googlecloud Upgraded Dataproc Metastore Proxy to v0.0.79 to fix CVEs. Fixed CVEs CVE-2026-24308 and CVE-2026-24281 1/2

    Post summary

    Google released an update to the Dataproc Metastore Proxy to address CVE-2026-24308 and CVE-2026-24281.

    1100084
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    Dataproc Serverless update on April 2, 2026 https://docs.cloud.google.com/dataproc-serverless/docs/release-notes/#April_02_2026 #googlecloud Upgraded Dataproc Metastore Proxy to v0.0.79 to fix CVEs. Fixed CVEs CVE-2026-24308 and CVE-2026-24281 1/2

    Post summary

    Google released an update to Dataproc Metastore Proxy, version 0.0.79, fixing CVE-2026-24308 and CVE-2026-24281.

    1000075
    1.8K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache ZooKeeper の脆弱性 CVE-2026-24308/24281 が FIX:機密ログの漏洩とサーバなりすましの恐れ https://iototsecnews.jp/2026/03/09/apache-zookeeper-flaw-exposes-sensitive-data-to-attackers/ 今回の脆弱性は、システムの土台を支える設定管理や検証の、不適切な仕組みに起因するものです。1 件目の CVE-2026-24308 は、本来は秘匿されるべき認証情報が INFO レベルのログとして出力されてしまう、コンフィグ処理の不備が原因です。開発時の確認用ログが、本番環境でも残ってしまったような状態といえます。 2件目の CVE-2026-24281 は、接続先の正当性を確かめるホスト名検証において、安全性の低い逆 DNS (PTR) ルックアップへ、自動的に切り替えが生じてしまう欠陥です。この経路を悪用する攻撃者は、偽のサーバになりすますことが可能になります。ご利用のチームは、ご注意ください。 #Apache #CVE202624281 #CVE202624308 #Vulnerability #ZooKeeper

    Post summary

    The piece discloses two ZooKeeper CVEs that expose sensitive data via logging and permit server spoofing through improper DNS verification, but does not provide PoC, exploit code, or patch details.

    01000109
    484 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Apache ZooKeeper vulnerabilities (CVE-2026-24281, CVE-2026-24308) allow PTR record spoofing and sensitive data leaks in logs. Update clusters immediately. #ApacheZooKeeper #CyberSecurity #InfoSec #Vulnerability #PatchAlert #DataLeak #ThreatIntel #AppSec https://securityonline.info/critical-bypasses-and-secret-leaks-patched-in-apache-zookeeper/ https://t.co/iIu78yQXGT

    Post summary

    The message highlights Apache ZooKeeper CVEs that enable PTR record spoofing and log-based data leakage, and it urges administrators to apply patches immediately.

    00010313
    10.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24308 (CVSS:7.5, HIGH) is Modified. Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an att..https://nvd.nist.gov/vuln/detail/CVE-2026-24308 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post discloses a high‑severity CVE (CVE-2026-24308) involving improper configuration handling in Apache ZooKeeper 3.8.5/3.9.4, with no indications of active exploitation, PoC, or patches.

    0000018
    172 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Alert: Critical vulnerabilities CVE-2026-24308 & CVE-2026-24281 found in Apache ZooKeeper. Immediate patching to versions 3.8.6 or 3.9.5 is essential. Link: https://thedailytechfeed.com/critical-flaws-in-apache-zookeeper-threaten-data-security-urgent-patches-released/ #Vulnerability #Security #Patch #Update #Apache #ZooKeeper #Data #Protection #Cyber #Threat #CVE #Network #Software #Tech #IT #Bugs #Fix #Urgent #Risk #System

    Post summary

    The post announces critical CVE‑2026‑24308 and CVE‑2026‑24281 in Apache ZooKeeper and urges users to apply patches immediately by updating to specific versions.

    000005
    260 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-24308: Sensitive information disclosure in client configuration handling CVE-2026-24281: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager ZooKeeper Security https://zookeeper.apache.org/security.html

    Post summary

    The post lists two ZooKeeper CVEs—one exposing sensitive configuration data and another permitting hostname verification bypass via reverse‑DNS fallback—without mentioning exploitation, patches, or PoC details.

    00000421
    6.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Apache ZooKeeper flaws expose secrets and weaken server identity checks Apache ZooKeeper patched two important flaws—CVE-2026-24308 and CVE-2026-24281—that can leak sensitive configuration data through logs and allow hostname verification bypass via reverse DNS fallback, raising the risk of credential exposure and man-in-the-middle scenarios. This matters because ZooKeeper is widely embedded in distributed environments, so weak logging hygiene or trust validation can cascade into broader infrastructure compromise. 🎯 Target: Global/Organizations Using Apache ZooKeeper #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/apache-zookeeper-vulnerability/

    Post summary

    Apache ZooKeeper has patched CVE-2026-24308 and CVE-2026-24281, which could leak configuration data through logs and allow bypass of hostname verification, thereby mitigating potential credential exposure.

    0000057
    273 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24308 Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored i… https://www.cve.org/CVERecord?id=CVE-2026-24308

    Post summary

    A short announcement identifies CVE-2026-24308 as a configuration-value handling flaw in Apache ZooKeeper that could expose sensitive data, with no evidence of PoC, exploitation, or patches.

    00000117
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-24308 - Apache ZooKeeper: Sensitive information disclosure in client configuration handling Intel Report: https://ift.tt/h0Vdzbe

    Post summary

    The tweet announces a newly identified CVE-2026-24308 affecting Apache ZooKeeper, describing it as a sensitive information disclosure vulnerability. No exploit, patch, or active exploitation details are provided.

    0000035
    344 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24308 Information Disclosure Vulnerability in Apache ZooKeeper Configuration Logging https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24308

    Post summary

    The text announces a newly identified information‑disclosure flaw in Apache ZooKeeper’s configuration logging, without mentioning any PoC, exploit tool, active attacks, or remediation.

    0000046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachezookeeper---

Explore more