CVE 9.4 CRITICAL

CVE-2026-11746_CVE-2026-11746

9.4 / 10
CRITICAL
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.

AI Analysis

Vulnerability in Central Dogma server allowing attackers to read or execute commands due to a hardcoded secret

Basic Information

ID CVE-2026-11746
Source LY-Corporation
Published Jun 22, 2026 at 02:35

Affected Product

Vendor LY Corporation
Product Central Dogma
Version 0.84.0

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor LY Corporation
Product Central Dogma
Version < 0.84.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.