Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35337

31
FAUCET Score

CVE-2026-35337 is a critical deserialization vulnerability in Apache Storm versions before 2.8.6 that allows authenticated users to achieve remote code execution. The flaw exists in the Nimbus Thrift API's handling of topology credentials, where a crafted serialized object can be injected into the TGT credential field and executed without proper validation. This vulnerability affects both Nimbus and Worker JVMs, potentially compromising the entire Storm cluster infrastructure. The vulnerability carries a CVSS score of 8.8 (High severity) with a network attack vector, low complexity, and low privileges required. An authenticated attacker can achieve complete compromise across confidentiality, integrity, and availability. While the EPSS score of 0.0017 indicates relatively low predicted probability of exploitation compared to other CVEs, the high CVSS rating reflects the severe potential impact if successfully exploited. There is currently no evidence of active exploitation in the wild, as indicated by its inactive status on the KEV catalog. However, the vulnerability does not appear on the Hot List, suggesting limited current community attention. Immediate mitigation is recommended through upgrading to version 2.8.6, with an interim monkey-patch solution available for ObjectInputFilter configuration if immediate patching is not feasible.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 2.8.6CPE matchmatch criteria
cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.01%
Probability of exploitation in next 30 days
EPSS Percentile
59.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0101 is in the 56th percentile among its peer group of 17,808 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (1)

apacheapache:www.mail-archive.com/[email protected]/msg10916.html

CVE-2026-35337: Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling

Apr 12, 2026

References

openwall.com / lists/oss-security/2026/04/12/6
Mailing ListThird Party Advisory
storm.apache.org / 2026/04/12/storm286-released.html
Release NotesVendor Advisory