Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-82434

Apache Storm: topology ZooKeeper credential disclosed to read-only users and logs

Technology

Apache Storm

CVSS Score

6.5 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

When ZooKeeper authentication is configured, Nimbus served the topology configuration, including storm.zookeeper.topology.auth.payload, to any caller with read-only topology permissions, and the submission client and SASL handlers wrote the payload to logs. The credential can write worker heartbeats, backpressure and error state for that topology. Apache advises rotating the payload and reviewing retained logs. The 6.5 score on NVD is from CISA-ADP; Apache, as the CNA, scored it 10.0 under CVSS 4.0.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.