CVE-2026-41081Disclosure(apache / storm)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTransportPlugin assigns a fallback principal (CN=ANONYMOUS) if no client certificate is presented or if certificate verification fails. The underlying SSLPeerUnverifiedException is caught and suppressed rather than rejecting the connection. This fail-open behavior means an unauthenticated client can establish a TLS connection and receive a valid principal identity. If the configured authorizer (e.g., SimpleACLAuthorizer) does not explicitly deny access to CN=ANONYMOUS, this may result in unauthorized access to Storm services. The condition is logged at debug level only, reducing visibility in production. Impact: Unauthenticated clients may be assigned a principal identity, potentially bypassing authorization in permissive or misconfigured environments. Mitigation: Users should upgrade to 2.8.7 in which TLS authentication failures are handled in a fail-closed manner. Users who cannot upgrade immediately should: - Enable mandatory client certificate authentication (nimbus.thrift.tls.client.auth.required: true) - Ensure authorization rules explicitly deny access to CN=ANONYMOUS - Review all ACL configurations for implicit default-allow behavior

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • storm

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
storm

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-25: 1Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 104-2504-2704-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-251
General1
2026-04-271
Disclosure1
2026-04-281
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Storm CVE-2026-40557: Prometheus Reporter: Disabling TLS verification for Reporter also disables it for all other connections https://www.openwall.com/lists/oss-security/2026/04/25/2 CVE-2026-41081: Client: Anonymous principal assigned on TLS client certificate verification failure https://www.openwall.com/lists/oss-security/2026/04/25/3

    Post summary

    The message announces two new CVEs affecting Apache Storm, detailing how TLS verification can be bypassed and certificate failures lead to anonymous access. No exploitation evidence, PoC, or patch is mentioned, making this a straightforward disclosure of vulnerability details.

    02072569
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41081 Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TL… https://www.cve.org/CVERecord?id=CVE-2026-41081

    Post summary

    The text announces CVE‑2026‑41081, a vulnerability in Apache Storm that causes anonymous principal assignment when TLS client authentication fails; no PoC or exploitation details are provided.

    0000088
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41081 CVE-2026-41081 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41081

    Post summary

    The post simply repeats the CVE identifier and includes a link, offering no substantive information about the vulnerability or its status.

    0000031
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachestorm---

Explore more