Logviewer Daemon Log Access Issue in Apache Storm
CVE-2026-82437

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82437?

The Logviewer in Apache Storm suffers from an access control issue that allows unauthorized users to access sensitive daemon logs. The flaw exists because the access decision for the daemon logs ignores configured user and group settings, allowing any user with servlet filtering to read critical log files, including nimbus.log and supervisor.log, across all nodes. Additionally, log listing endpoints fail to filter user arguments, exposing all tenant log file names. Immediate mitigation involves upgrading to version 3.1.0, which rectifies these access control flaws by applying the necessary user group filters to daemon logs. For users unable to upgrade, placing the Logviewer behind a reverse proxy is advised to restrict access to daemon logs.

Affected Version(s)

Apache Storm Logviewer 3.0.0 < 3.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The ASF using Claude Agents
.