---
id: CVE-2026-11746
title: >-
  A vulnerability has been identified in centraldogma-server versions prior to
  0.84.0, where enabling ZooKeeper replication without setting
  replication.secret causes the server to silently fall back to a hard-coded,
  publicly known secret
summary: >-
  A vulnerability has been identified in centraldogma-server versions prior to
  0.84.0, where enabling ZooKeeper replication without setting
  replication.secret causes the server to silently fall back to a hard-coded,
  publicly known secret. …
severity: critical
cvss: 9.4
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-798
vendor: LY Corporation
product: Central Dogma
affected:
  - central_dogma (all versions)
published: '2026-06-22'
updated: '2026-06-22'
sourceUpdated: '2026-06-22T20:21:28.783'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11746'
references:
  - url: >-
      https://github.com/line/centraldogma/security/advisories/GHSA-2j95-gqxf-v3vg
    label: dl_cve@linecorp.com
  - url: >-
      https://github.com/line/centraldogma/security/advisories/GHSA-2j95-gqxf-v3vg
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-22T16:12:56.884349Z'
cvssSource: cna
ingestedAt: '2026-09-14T04:33:06.888Z'
epss: 0.00229
epssPercentile: 0.12156
---

## Overview

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
