Access Control Vulnerability in Apache Storm by The Apache Software Foundation
CVE-2026-82431
Currently unrated
What is CVE-2026-82431?
The vulnerability in Apache Storm's SimpleACLAuthorizer component allows for unauthorized access by failing to evaluate group restrictions correctly when user lists are empty. This oversight can lead to unintended access to user-level operations such as 'submitTopology', 'beginFileUpload', and 'getNimbusConf' for all authenticated users, compromising the security of the entire cluster. Operators who follow the documentation may wrongly assume their clusters are secure, as the vulnerability operates silently without any indications in logs or settings. To mitigate the issue, users should upgrade to version 3.1.0 or ensure that 'nimbus.users' is populated to enforce group evaluations.
Affected Version(s)
Apache Storm Client 3.0.0 < 3.1.0