Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-82433

Apache Storm: unredacted daemon configuration through Nimbus and the UI

Technology

Apache Storm

CVSS Score

6.5 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

getNimbusConf returned the full daemon configuration, including storm.zookeeper.auth.payload and the TLS keystore and truststore passwords, after only a user-level check, and the UI endpoint /api/v1/cluster/configuration applied no per-user check at all. Apache advises rotating the ZooKeeper authentication payload and any TLS store passwords that were reachable. The 6.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.