A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.
CVSS
No CVSS.
References
Configurations
No configuration.
History
22 Jun 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/line/centraldogma/security/advisories/GHSA-2j95-gqxf-v3vg - | |
| CWE | CWE-798 |
22 Jun 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-22 03:16
Updated : 2026-06-22 20:21
NVD link : CVE-2026-11746
Mitre link : CVE-2026-11746
CVE.ORG link : CVE-2026-11746
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
