CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

CVE-2026-82431: Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7176

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-82431: Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users

Apache Storm Client versions before 3.1.0 contain an authorization bypass vulnerability where SimpleACLAuthorizer returns early if nimbus.users is empty, bypassing nimbus.groups restrictions. Operators who configured group-level access control without setting nimbus.users would grant unrestricted access to all authenticated principals. The vulnerability was introduced in version 3.0.0 and is rated important severity.

Why it matters: Organizations running Apache Storm Client 3.0.0 through 3.0.x should upgrade to 3.1.0 immediately, as unpatched clusters configured with group restrictions alone have no actual access controls in place.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary