CVE-2026-35337 is a critical deserialization vulnerability in Apache Storm versions before 2.8.6 that allows authenticated users to achieve remote code execution. The flaw exists in the Nimbus Thrift API's handling of topology credentials, where a crafted serialized object can be injected into the TGT credential field and executed without proper validation. This vulnerability affects both Nimbus and Worker JVMs, potentially compromising the entire Storm cluster infrastructure. The vulnerability carries a CVSS score of 8.8 (High severity) with a network attack vector, low complexity, and low privileges required. An authenticated attacker can achieve complete compromise across confidentiality, integrity, and availability. While the EPSS score of 0.0017 indicates relatively low predicted probability of exploitation compared to other CVEs, the high CVSS rating reflects the severe potential impact if successfully exploited. There is currently no evidence of active exploitation in the wild, as indicated by its inactive status on the KEV catalog. However, the vulnerability does not appear on the Hot List, suggesting limited current community attention. Immediate mitigation is recommended through upgrading to version 2.8.6, with an interim monkey-patch solution available for ObjectInputFilter configuration if immediate patching is not feasible.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.8.6CPE matchmatch criteria | cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.