Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-82437

Apache Storm Logviewer: log access controls not enforced for daemon logs

Technology

Apache Storm

CVSS Score

4.3 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

The Logviewer did not apply logs.users and logs.groups to daemon logs, so any user who passed the servlet filter could read nimbus.log, supervisor.log and other daemon logs on every reachable node, and its listing endpoints returned every tenant's log file names. No configuration closed either behaviour. The 4.3 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.