Junglewise Threat Intelligence

CVE-2026-82433: Apache Storm credential exposure via unredacted configuration

CVE-2026-82433 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apache Storm. Vendors: Apache.

Executive brief

Apache Storm is a distributed real-time stream processing system used to handle high-volume data pipelines. A vulnerability in the configuration API endpoints exposed sensitive credentials—including ZooKeeper authentication payloads and TLS keystore/truststore passwords—to any user with basic access to the UI, due to missing authorization checks and unredacted credential values in API responses.

Technical details

The vulnerability consists of two authorization and disclosure flaws: (1) the `getNimbusConf` RPC method performed only user-level authorization but returned the complete daemon configuration without redacting sensitive values such as `storm.zookeeper.auth.payload` and TLS passwords; (2) the UI endpoint `/api/v1/cluster/configuration` lacked the `@AuthNimbusOp` annotation, causing the authorization filter to treat it as unrestricted and apply no per-user checks, proxying requests under the UI daemon's own principal. This allowed any user who passed the basic UI filter to retrieve the full configuration including credentials that Nimbus would have refused. The vulnerability is network-reachable via the UI and requires only UI-level access to exploit. An attacker can obtain credentials used for ZooKeeper authentication and TLS connections, enabling further compromise of the Storm cluster and its associated infrastructure.

Affected products

  • Apache Storm before 3.1.0

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: fix released in version 3.1.0

References

Related threats