External risk intelligence

Apache Storm ZooKeeper Credentials Exposed via Topology Configuration and Logs

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-82434

Apache Storm is a distributed stream processing framework typically deployed within internal data centers or private networks. While it involves network communication, it is not designed to be exposed directly to the public internet, and access is generally restricted to authenticated internal users or services.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE involves Apache Storm, a system for processing data streams. It relates to how the system handles credentials, potentially exposing them to unauthorized viewing and allowing manipulation of cluster state for specific topologies. The main concern is confirming relevance and exposure.

  • A credential leak could allow unauthorized access.
  • Sensitive data exposure or state manipulation is possible.
  • Confirm relevance and verify any exposure to sensitive data.

Attack Path

How an attacker could exploit the issue

An attacker could gain access to sensitive ZooKeeper credentials by exploiting a misconfiguration in Apache Storm's authentication handling. This occurs when Nimbus, the Storm scheduler, serves topology configurations containing ZooKeeper authentication details to any user with read-only permissions. Attackers who can view a topology's configuration, even without write access, can therefore obtain credentials that grant them write capabilities. These credentials could then be used to alter or delete topology state, such as heartbeats or backpressure information.

  • Read-only topology access required.
  • Nimbus serves sensitive credentials.
  • Compromise topology state.

Live Threat

Current exploitation, exposure, and threat context

When ZooKeeper authentication is configured, a credential used to manage topology state could be exposed to unauthorized users who only have read-only access to view topology configurations. This exposure could occur if these users request topology information, leading to the credential being served to them verbatim. The credential is not read-only and may allow manipulation of topology state. Additionally, the credential could be logged and included in support bundles.

  • Topology management credential.
  • Served to read-only topology viewers.
  • Topology state could be altered.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Apache Storm platform team and the application owners managing Storm topologies are likely responsible for addressing this vulnerability. The first practical step is to identify all deployed Storm clusters and topologies, confirm their exposure and criticality, and then determine the specific owners of those topologies to plan remediation.

  • Owner: Platform and application owners.
  • Verify: Topology reachability and criticality.
  • Action: Plan coordinated upgrade or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache Storm and how does it use ZooKeeper?

Apache Storm is a distributed framework designed for real-time processing of massive data streams. It relies on Apache ZooKeeper to manage its cluster state, such as tracking worker nodes, coordinating tasks, and handling configuration data. In environments where security is enabled, specific authentication credentials are used to ensure that only authorized components can interact with this shared state.

What does CVE-2026-82434 mean for my system's security?

This vulnerability involves the improper protection of credentials, classified under CWE-522 and CWE-532. It means that sensitive authentication tokens intended for system workers are being leaked to users with read-only access. Because these tokens carry write permissions, an unauthorized party could manipulate specific topology states like heartbeats or error reporting, even if they were never granted administrative rights.

Does viewing a topology always trigger this credential leak?

The leak occurs when the Nimbus service provides the full topology configuration, which contains the sensitive authentication payload, to a caller. It is not triggered by simply having access to the cluster; the risk is present whenever a user or service requests topology configuration details while ZooKeeper authentication is actively configured. If authentication is not enabled for ZooKeeper, this specific credential exposure does not apply.

Is my Apache Storm deployment at high risk?

According to Halo Surface Signal, Apache Storm is generally deployed within private, internal networks and is not meant for public internet exposure, making widespread external access unlikely. However, the risk remains significant for internal environments where users with limited read-only permissions might have access to topology configurations or where log files and support bundles containing these credentials are stored and accessible to unauthorized staff.

How do I secure my infrastructure against this threat?

The primary resolution is upgrading to version 3.1.0, which stops the inclusion of credentials in configuration data and logs. If you cannot upgrade immediately, you must rotate your existing ZooKeeper authentication payloads. Additionally, audit your log files and support bundles to purge any exposed credentials and strictly limit who can access topology configurations to only those users who absolutely require that information.

References