Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-82433
Apache Storm: unredacted daemon configuration through Nimbus and the UI
Technology
Apache Storm
CVSS Score
6.5 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
getNimbusConf returned the full daemon configuration, including storm.zookeeper.auth.payload and the TLS keystore and truststore passwords, after only a user-level check, and the UI endpoint /api/v1/cluster/configuration applied no per-user check at all. Apache advises rotating the ZooKeeper authentication payload and any TLS store passwords that were reachable. The 6.5 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.