Skip to main content

CVE-2026-84179: CWE-522: Insufficiently Protected Credentials in Apache Software Foundation Apache Storm Nimbus

0
High
VulnerabilityCVE-2026-84179cvecve-2026-84179cwe-522cwe-200
Published: 09/14/2026 (09/14/2026, 13:57:59 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Storm Nimbus

Description

CVE-2026-84179 is a vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It involves insufficient protection of sensitive credentials in the Nimbus API, where the getTopologyPageInfo operation returns merged configuration data including sensitive credentials without redaction. This allows principals with read-only topology access to view sensitive daemon credentials such as ZooKeeper authentication payloads and TLS keystore passwords. The issue is fixed in version 3.1.0 by masking credential-bearing values before serving configuration data.

Affected software

Apache Software Foundation

Apache Storm Nimbus

Affected versions
>=3.0.0 <3.1.0

Apache Software Foundation

Apache Storm UI

Affected versions
>=3.0.0 <3.1.0
Apache Software Foundation/org.apache.storm:storm-server
pkg:maven/Apache Software Foundation/org.apache.storm:storm-server
Affected versions
>=3.0.0 <3.1.0
Apache Software Foundation/org.apache.storm:storm-webapp
pkg:maven/Apache Software Foundation/org.apache.storm:storm-webapp
Affected versions
>=3.0.0 <3.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 14:47:15 UTC

Technical Analysis

The vulnerability arises because the getTopologyPageInfo API call merges the Nimbus daemon configuration with the topology's configuration and returns it without redacting sensitive credential information in the topology_conf field. This includes sensitive data such as storm.zookeeper.auth.payload, TLS keystore and truststore passwords, and plugin keys marked as secrets. Under the SimpleACLAuthorizer, users with read-only topology access (topology.readonly.users or topology.readonly.groups) can access these credentials, bypassing the more restrictive access controls applied to the dedicated cluster configuration API getNimbusConf. The vulnerability is addressed in Apache Storm Nimbus 3.1.0 by masking credential-bearing values before any configuration is served via the Nimbus API.

Potential Impact

Unauthorized users with read-only topology access can obtain sensitive cluster credentials, including ZooKeeper authentication payloads and TLS keystore/truststore passwords. This exposure could lead to compromise of cluster security and unauthorized access to protected resources. The vulnerability does not require elevated privileges beyond read-only topology access but exposes highly sensitive configuration data.

Mitigation Recommendations

Upgrade to Apache Storm Nimbus version 3.1.0 or later, where credential-bearing values are masked before configuration data is served via the Nimbus API. For users unable to upgrade immediately, remove any principals not fully trusted with cluster credentials from topology.readonly.users, topology.readonly.groups, topology.users, and topology.groups. Additionally, rotate the ZooKeeper authentication payload and any TLS keystore or truststore passwords that may have been exposed through the topology page.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-09-01T09:25:56.223Z
State
PUBLISHED

Threat ID: 6aa8057455bf5e2cf52f81d0

Added to database: 09/14/2026, 14:32:20 UTC

Last enriched: 09/14/2026, 14:47:15 UTC

Last updated: 09/14/2026, 14:47:15 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses