Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-82430

Apache Storm worker-launcher: root through Docker and OCI command files handed to the tenant

Technology

Apache Storm

CVSS Score

7.8 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0; the worker-launcher must be rebuilt and reinstalled

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

For Docker and OCI workers, the setuid-root worker-launcher changes ownership of the worker directory to the topology user before reading the command file in it, so the tenant can rewrite the file and have a container started as root with host paths mounted. Apache's interim advice is to disable Docker and OCI worker isolation or restrict submission to trusted principals. The 7.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.