CVE-2026-82438
Apache Storm: authenticated UI, Logviewer and DRPC responses readable from other origins
Technology
Apache Storm
CVSS Score
8.1 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
The Logviewer reflected the request Origin in a credentialed CORS response, the shared CORS filter was misconfigured so the container's credential-allowing defaults applied, and the UI and Logviewer wrapped every GET response in a caller-supplied JSONP callback. A page an authenticated operator visits could read cluster, topology and log data. 3.1.0 adds ui.enable.jsonp, off by default. The 8.1 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.