CLEANSTART-2026-GJ18736

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-GJ18736
Upstream
Published
2026-10-08T00:42:12Z
Modified
2026-10-08T16:47:06Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
`deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL re...
Details

CVE-2026-79993 affects multiple packages. The deleteContainer opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the znode or its parent. See references for individual vulnerability details.

References

Affected packages

CleanStart / solr

Package

Name
solr
Purl
pkg:apk/cleanstart/solr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.10.1-r10

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json"

CleanStart / solr

Package

Name
solr
Purl
pkg:apk/cleanstart/solr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.8.1-r4

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json"

CleanStart / wso2is

Package

Name
wso2is
Purl
pkg:apk/cleanstart/wso2is

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.2.0-r2

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json"

CleanStart / spark-sc213-jdk17-py312

Package

Name
spark-sc213-jdk17-py312
Purl
pkg:apk/cleanstart/spark-sc213-jdk17-py312

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.2.0-r4

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json"