Privilege Escalation Vulnerability in Apache Storm Docker and OCI Worker
CVE-2026-82430
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 14 September 2026
What is CVE-2026-82430?
A design flaw in Apache Storm's Docker and OCI worker processes allows an untrusted user to exploit the ownership change sequence of the worker directory. This occurs when the worker-launcher modifies the ownership of the worker directory before validating the command file. An attacker can replace this command file during the brief window between the ownership change and the subsequent read, leading to the execution of arbitrary commands with root privileges. The lack of stringent validation measures on command file sources enables potential unauthorized access to host resources and allows users to exploit structural validations, resulting in extensive security ramifications. Users are advised to upgrade to version 3.1.0 for enhanced security measures to mitigate this vulnerability.
Affected Version(s)
Apache Storm Worker Launcher 3.0.0 < 3.1.0