Security Flaw in Worker-Launcher Binary Affects Apache Storm
CVE-2026-82429

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82429?

The worker-launcher binary in Apache Storm is susceptible to a vulnerability that allows a tenant executing code on a supervisor node to manipulate file ownership and permissions. This is achieved by placing a symbolic link within the directory structure, effectively redirecting privileged operations like lchown and chmod on the root-owned files to arbitrary locations. This flaw compromises the intended isolation provided by the supervisor configuration and poses serious risks related to unauthorized access and control. The recommended action for users is to upgrade to version 3.1.0 to mitigate this risk, ensuring proper security protocols are maintained.

Affected Version(s)

Apache Storm Worker Launcher 3.0.0 < 3.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The ASF using Claude Agents
.