THREATOPS
THREAT OPSThreat News › CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer

CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer

medoss_secPublished 2026-09-13

<p>Posted by Richard Zowalla on Sep 13</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Storm Logviewer (org.apache.storm:storm-webapp) 3.0.0 before 3.1.0<br /> <br /> Description:<br /> <br /> Description<br /> <br /> The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For<br /> daemon logs those settings were not appl

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/743