Junglewise Threat Intelligence

CVE-2026-82434: Apache Storm credential exposure in topology configuration

CVE-2026-82434 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apache Storm. Vendors: Apache.

Executive brief

Apache Storm, a distributed stream processing framework, stores ZooKeeper authentication credentials in topology configuration files. These credentials are visible to users with only read-only permission to view topology configurations, and were also accidentally logged during submissions and in debug logs. An attacker with read-only access can extract these credentials and use them to forge or manipulate cluster state, disrupting topology operations.

Technical details

The vulnerability is a credential exposure flaw in Apache Storm's handling of ZooKeeper authentication payloads. The `storm.zookeeper.topology.auth.payload` is deliberately retained in topology configuration to support worker operations, but Nimbus (the cluster master) served this configuration verbatim to any caller with read-only topology permissions. Additionally, the submission client and SASL handlers logged this payload at INFO and DEBUG levels respectively. An attacker with read-only topology view permissions or access to logs/support bundles can extract the ZooKeeper credential and use it to forge worker state (heartbeats, backpressure, errors) for targeted topologies, though not for write operations on assignments. The fix in version 3.1.0 removes the payload from configurations served to read-only callers and suppresses logging of the payload.

Affected products

  • Apache Storm prior to 3.1.0

Timeline

  • 2026-09-14: disclosed

References

Related threats