Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-82429

Apache Storm worker-launcher: local privilege escalation to root through a time-of-check race

Technology

Apache Storm

CVSS Score

7.8 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0; the worker-launcher must be rebuilt and reinstalled

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

The setuid-root worker-launcher calls lchown and chmod on full pathnames inside trees the topology user can write, after classifying each entry. A tenant can swap a directory for a symlink in between and redirect the root-owned operation at any file on the host, crossing the boundary that supervisor.run.worker.as.user is meant to enforce. The 7.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.