Security Flaw in Worker-Launcher Binary Affects Apache Storm
CVE-2026-82429
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 14 September 2026
What is CVE-2026-82429?
The worker-launcher binary in Apache Storm is susceptible to a vulnerability that allows a tenant executing code on a supervisor node to manipulate file ownership and permissions. This is achieved by placing a symbolic link within the directory structure, effectively redirecting privileged operations like lchown and chmod on the root-owned files to arbitrary locations. This flaw compromises the intended isolation provided by the supervisor configuration and poses serious risks related to unauthorized access and control. The recommended action for users is to upgrade to version 3.1.0 to mitigate this risk, ensuring proper security protocols are maintained.
Affected Version(s)
Apache Storm Worker Launcher 3.0.0 < 3.1.0