CVE-2026-41081
medium
CVSS v3
6.5
CVSS v2
—
VIR risk
6.5
Description
Apache Storm's Improper Handling of TLS Client Authentication Failure Leads to Anonymous Principal Assignment
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@apache.org — https://lists.apache.org/thread/plxx5l29dvplk5rwzdcq53rdfl6v4gs8
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.storm:storm-client | <2.8.7 | 2.8.7 |
| MAVEN | org.apache.storm:storm-client | < 2.8.7 | 2.8.7 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | storm | {"endExcluding":"2.8.7"} | 2.8.7 |
References
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.