CVE-2026-82430
Apache Storm worker-launcher: root through Docker and OCI command files handed to the tenant
Technology
Apache Storm
CVSS Score
7.8 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0; the worker-launcher must be rebuilt and reinstalled
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
For Docker and OCI workers, the setuid-root worker-launcher changes ownership of the worker directory to the topology user before reading the command file in it, so the tenant can rewrite the file and have a container started as root with host paths mounted. Apache's interim advice is to disable Docker and OCI worker isolation or restrict submission to trusted principals. The 7.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.