Privilege Escalation Vulnerability in Apache Storm Docker and OCI Worker
CVE-2026-82430

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82430?

A design flaw in Apache Storm's Docker and OCI worker processes allows an untrusted user to exploit the ownership change sequence of the worker directory. This occurs when the worker-launcher modifies the ownership of the worker directory before validating the command file. An attacker can replace this command file during the brief window between the ownership change and the subsequent read, leading to the execution of arbitrary commands with root privileges. The lack of stringent validation measures on command file sources enables potential unauthorized access to host resources and allows users to exploit structural validations, resulting in extensive security ramifications. Users are advised to upgrade to version 3.1.0 for enhanced security measures to mitigate this vulnerability.

Affected Version(s)

Apache Storm Worker Launcher 3.0.0 < 3.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The ASF using Claude Agents
.