CVE-2026-82426
Apache Storm Nimbus: arbitrary file read through an unvalidated uploaded jar location
Technology
Apache Storm
CVSS Score
6.5 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
Nimbus accepted the uploadedJarLocation argument of submitTopology as any server-side path, copied the file into the topology's jar blob and granted the submitter read access to it. Any file the Nimbus user can read, such as its Kerberos keytab, TLS private keys or storm.yaml with the ZooKeeper authentication payload, could be retrieved. Where nimbus.users is unset, every authenticated principal can submit. The 6.5 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.