{"id":"CLEANSTART-2026-GJ18736","summary":"`deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL re...","details":"CVE-2026-79993 affects multiple packages. The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the znode or its parent. See references for individual vulnerability details.","modified":"2026-10-08T16:47:06.775309627Z","published":"2026-10-08T00:42:12.095108Z","upstream":["CVE-2026-79993"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-GJ18736.json"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-79993"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79993"}],"affected":[{"package":{"name":"solr","ecosystem":"CleanStart","purl":"pkg:apk/cleanstart/solr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.10.1-r10"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json"}},{"package":{"name":"solr","ecosystem":"CleanStart","purl":"pkg:apk/cleanstart/solr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.8.1-r4"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json"}},{"package":{"name":"wso2is","ecosystem":"CleanStart","purl":"pkg:apk/cleanstart/wso2is"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.2.0-r2"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json"}},{"package":{"name":"spark-sc213-jdk17-py312","ecosystem":"CleanStart","purl":"pkg:apk/cleanstart/spark-sc213-jdk17-py312"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.0-r4"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-GJ18736.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}