Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-82427

Apache Storm: path traversal as the supervisor user through blobstore map local names

Technology

Apache Storm

CVSS Score

7.8 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

The local name a submitter chooses for each blob in topology.blobstore.map was used to build a path without normalisation, and the symlink helper deletes whatever exists at the target first. A submitter could use ../ segments to delete content and plant symlinks as the supervisor user on every node the topology runs on, including making a later worker launch run attacker-chosen code as another tenant. The 7.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.