Server-Side Path Vulnerability in Apache Storm by Apache Software Foundation
CVE-2026-82426
Currently unrated
What is CVE-2026-82426?
A vulnerability in Apache Storm allows authenticated users with topology submission rights to submit arbitrary file paths readable by the Nimbus daemon. This flaw arises because the 'uploadedJarLocation' argument is accepted as a server-side path without adequate validation of its origin. An attacker can exploit this to bypass the intended file upload workflow, potentially exposing sensitive files such as Nimbus Kerberos keytabs and TLS private keys. Recommendations include upgrading to version 3.1.0 or restricting user access to trusted principals.
Affected Version(s)
Apache Storm Nimbus 3.0.0 < 3.1.0