CVE-2026-82427
Apache Storm: path traversal as the supervisor user through blobstore map local names
Technology
Apache Storm
CVSS Score
7.8 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
The local name a submitter chooses for each blob in topology.blobstore.map was used to build a path without normalisation, and the symlink helper deletes whatever exists at the target first. A submitter could use ../ segments to delete content and plant symlinks as the supervisor user on every node the topology runs on, including making a later worker launch run attacker-chosen code as another tenant. The 7.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.