Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-24281

31
FAUCET Score

CVE-2026-24281 describes a hostname verification bypass in Apache ZooKeeper's ZKTrustManager. When IP SAN validation fails, the system improperly falls back to reverse DNS (PTR) records, allowing attackers who control or spoof these records to impersonate ZooKeeper servers or clients. This vulnerability requires the attacker to present a certificate trusted by ZKTrustManager, making exploitation more challenging. The attack vector involves manipulating PTR records, with a moderate complexity due to the certificate trust requirement. The potential impact is the impersonation of ZooKeeper components, leading to unauthorized access or disruption. The FAUCET Risk Score is 27/100, and its EPSS score is very low, indicating a low likelihood of exploitation in the wild. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion is minimal, with only two mentions. Users are advised to upgrade to ZooKeeper versions 3.8.6 or 3.9.5, which introduce a configuration option to disable reverse DNS lookup.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.8.0, < 3.8.6CPE matchmatch criteria
cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*
>= 3.9.0, < 3.9.5CPE matchmatch criteria
cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*
>= 3.8.0, <= 3.8.5CPE match
cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*
>= 3.9.0, <= 3.9.4CPE match
cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.63%
Probability of exploitation in next 30 days
EPSS Percentile
46.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 18th percentile among its peer group of 8,915 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: org.apache.zookeeper:zookeeperFixed in: 3.8.6
mavenpatch availablevia ghsa
Product: org.apache.zookeeper:zookeeperFixed in: 3.9.5
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

mavenGHSA-7xrh-hqfc-g7qrhigh

Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager

Mar 7, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10789.html

CVE-2026-24281: Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager

Mar 7, 2026

References

access.redhat.com / errata/RHSA-2026:10184
access.redhat.com / errata/RHSA-2026:14272
access.redhat.com / errata/RHSA-2026:14276
access.redhat.com / errata/RHSA-2026:34608
access.redhat.com / errata/RHSA-2026:8509
access.redhat.com / security/cve/CVE-2026-24281
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-24281.json
openwall.com / lists/oss-security/2026/03/07/4
Mailing ListThird Party Advisory
lists.apache.org / thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2
Mailing ListVendor Advisory