Threats Tagged 'cve-2026-82434'
View all threats tagged with 'cve-2026-82434'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-82434'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-82434 is a critical vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. When ZooKeeper authentication is enabled, the system exposes the ZooKeeper credential `storm.zookeeper.topology.auth.payload` to users with read-only topology permissions, allowing them to access a credential that grants write capabilities to certain cluster state operations. Additionally, this credential was logged in submission client logs and SASL handlers, potentially exposing it through log aggregation or support bundles. The vulnerability allows unauthorized modification or removal of topology state data related to worker heartbeats, backpressure, and error states. The issue is fixed in version 3.1.0, which removes the credential from configurations served to read-only users and stops logging it. Join the discussion | CVE Database V5 | 09/14/2026, 14:10:15 UTC Added: 09/14/2026, 14:32:18 UTC |
Showing 1 to 1 of 1 result