CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-84179: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7169

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-84179: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page

CVE-2026-84179 affects Apache Storm Nimbus and UI versions 3.0.0 before 3.1.0, where the topology page endpoint merges and exposes unredacted daemon configuration data. The vulnerability allows sensitive Nimbus configuration to be disclosed through the topology_conf field without filtering.

Why it matters: Organizations running Storm 3.0.0 must patch to 3.1.0 immediately, as unredacted daemon configuration exposed through the UI may contain credentials or other sensitive parameters used for authentication and system control.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary