CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-82438: Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7172

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-82438: Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins

CVE-2026-82438 affects Apache Storm Webapp versions 3.0.0 before 3.1.0, exposing authenticated application programming interface (API) responses to unrelated web origins through three separate mechanisms including reflected Origin header handling and credentials transmission. The vulnerability allows cross-origin requests to access authenticated user data via the Logviewer and other HTTP components.

Why it matters: Organizations running vulnerable Storm Webapp versions expose authenticated API responses to cross-site request forgery attacks; immediate patching to 3.1.0 or later is required to prevent credential-based data exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary