CVE-2026-82429
Apache Storm worker-launcher: local privilege escalation to root through a time-of-check race
Technology
Apache Storm
CVSS Score
7.8 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0; the worker-launcher must be rebuilt and reinstalled
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
The setuid-root worker-launcher calls lchown and chmod on full pathnames inside trees the topology user can write, after classifying each entry. A tenant can swap a directory for a symlink in between and redirect the root-owned operation at any file on the host, crossing the boundary that supervisor.run.worker.as.user is meant to enforce. The 7.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.