CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

Re: CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7168

As cited

Copy frozen at (site build).

vulnerabilities

Re: CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs

CVE-2026-82434 affects Apache Storm Nimbus and Apache Storm Client, exposing ZooKeeper credentials to read-only users and logs. The poster questions whether the vulnerability has an assigned severity rating.

Why it matters: Apache Storm operators should assess whether their ZooKeeper credentials may be accessible to read-only users and in logs, and determine if they can upgrade to a patched version.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary