CVE-2026-82434
Apache Storm: topology ZooKeeper credential disclosed to read-only users and logs
Technology
Apache Storm
CVSS Score
6.5 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
When ZooKeeper authentication is configured, Nimbus served the topology configuration, including storm.zookeeper.topology.auth.payload, to any caller with read-only topology permissions, and the submission client and SASL handlers wrote the payload to logs. The credential can write worker heartbeats, backpressure and error state for that topology. Apache advises rotating the payload and reviewing retained logs. The 6.5 score on NVD is from CISA-ADP; Apache, as the CNA, scored it 10.0 under CVSS 4.0.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.