CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7173

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer

Apache Storm Logviewer versions 3.0.0 before 3.1.0 fail to enforce configured access controls on daemon logs, allowing unauthorized users to read restricted log content. The vulnerability stems from improper logic that combines daemon log detection with authorization results, effectively bypassing the `logs.users` and `logs.groups` access restrictions operators configure.

Why it matters: Storm operators using versions prior to 3.1.0 face information disclosure risk if they rely on log access controls to protect sensitive data in daemon logs; patching or upgrading to 3.1.0 is needed to restore intended access restrictions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary