CVE-2026-24281 describes a hostname verification bypass in Apache ZooKeeper's ZKTrustManager. When IP SAN validation fails, the system improperly falls back to reverse DNS (PTR) records, allowing attackers who control or spoof these records to impersonate ZooKeeper servers or clients. This vulnerability requires the attacker to present a certificate trusted by ZKTrustManager, making exploitation more challenging. The attack vector involves manipulating PTR records, with a moderate complexity due to the certificate trust requirement. The potential impact is the impersonation of ZooKeeper components, leading to unauthorized access or disruption. The FAUCET Risk Score is 27/100, and its EPSS score is very low, indicating a low likelihood of exploitation in the wild. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion is minimal, with only two mentions. Users are advised to upgrade to ZooKeeper versions 3.8.6 or 3.9.5, which introduce a configuration option to disable reverse DNS lookup.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.8.0, < 3.8.6CPE matchmatch criteria | cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:* | ||
>= 3.9.0, < 3.9.5CPE matchmatch criteria | cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:* | ||
>= 3.8.0, <= 3.8.5CPE match | cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:* | ||
>= 3.9.0, <= 3.9.4CPE match | cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Mar 7, 2026CVE-2026-24281: Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
Mar 7, 2026