Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ly Corporation
Ly Corporation central Dogma |
|
| Vendors & Products |
Ly Corporation
Ly Corporation central Dogma |
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ZooKeeper Replication Default Secret Exposes Full Replication Log and Arbitrary Command Execution | |
| Weaknesses | CWE-287 CWE-798 |
Mon, 22 Jun 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: LY-Corporation
Published:
Updated: 2026-06-22T16:13:00.513Z
Reserved: 2026-06-09T06:48:47.296Z
Link: CVE-2026-11746
Updated: 2026-06-22T16:12:41.611Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:03:45Z