Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-41081

Apache Storm: TLS client authentication failure assigns an anonymous principal

Technology

Apache Storm

CVSS Score

6.5 / 10.0

Affected Versions

Apache Storm before 2.8.7

Upstream Fix

2.8.7

Published

April 27, 2026

OSSeva Coverage

Fixed upstream

Description

With TLS transport enabled and client certificates not required, the default, TlsTransportPlugin assigns the principal CN=ANONYMOUS when no certificate is presented or verification fails, instead of rejecting the connection. If the authorizer does not explicitly deny that principal, an unauthenticated client may reach Storm services. Apache recommends requiring client certificates and denying CN=ANONYMOUS until the upgrade. The 6.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm before 2.8.7, you need this patch. Book a discovery call to get covered.