Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-82426

Apache Storm Nimbus: arbitrary file read through an unvalidated uploaded jar location

Technology

Apache Storm

CVSS Score

6.5 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

Nimbus accepted the uploadedJarLocation argument of submitTopology as any server-side path, copied the file into the topology's jar blob and granted the submitter read access to it. Any file the Nimbus user can read, such as its Kerberos keytab, TLS private keys or storm.yaml with the ZooKeeper authentication payload, could be retrieved. Where nimbus.users is unset, every authenticated principal can submit. The 6.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.