Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-82437
Apache Storm Logviewer: log access controls not enforced for daemon logs
Technology
Apache Storm
CVSS Score
4.3 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
The Logviewer did not apply logs.users and logs.groups to daemon logs, so any user who passed the servlet filter could read nimbus.log, supervisor.log and other daemon logs on every reachable node, and its listing endpoints returned every tenant's log file names. No configuration closed either behaviour. The 4.3 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.