CVE-2026-41081
Apache Storm: TLS client authentication failure assigns an anonymous principal
Technology
Apache Storm
CVSS Score
6.5 / 10.0
Affected Versions
Apache Storm before 2.8.7
Upstream Fix
2.8.7
Published
April 27, 2026
OSSeva Coverage
Fixed upstream
Description
With TLS transport enabled and client certificates not required, the default, TlsTransportPlugin assigns the principal CN=ANONYMOUS when no certificate is presented or verification fails, instead of rejecting the connection. If the authorizer does not explicitly deny that principal, an unauthenticated client may reach Storm services. Apache recommends requiring client certificates and denying CN=ANONYMOUS until the upgrade. The 6.5 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm before 2.8.7, you need this patch. Book a discovery call to get covered.