Server-Side Path Vulnerability in Apache Storm by Apache Software Foundation
CVE-2026-82426

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82426?

A vulnerability in Apache Storm allows authenticated users with topology submission rights to submit arbitrary file paths readable by the Nimbus daemon. This flaw arises because the 'uploadedJarLocation' argument is accepted as a server-side path without adequate validation of its origin. An attacker can exploit this to bypass the intended file upload workflow, potentially exposing sensitive files such as Nimbus Kerberos keytabs and TLS private keys. Recommendations include upgrading to version 3.1.0 or restricting user access to trusted principals.

Affected Version(s)

Apache Storm Nimbus 3.0.0 < 3.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
The ASF using Claude Agents
.