Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ZooKeeper Replication Default Secret Exposes Full Replication Log and Arbitrary Command Execution | |
| Weaknesses | CWE-287 CWE-798 |
Mon, 22 Jun 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster. | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: LY-Corporation
Published:
Updated: 2026-06-22T16:13:00.513Z
Reserved: 2026-06-09T06:48:47.296Z
Link: CVE-2026-11746
Updated: 2026-06-22T16:12:41.611Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T05:00:06Z