Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-82431

Apache Storm: nimbus.groups ignored when nimbus.users is empty

Technology

Apache Storm

CVSS Score

9.8 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

SimpleACLAuthorizer returned early when nimbus.users was empty, before nimbus.groups was considered, so a cluster restricted by group alone had no restriction: every authenticated principal could perform every user-level operation, including submitTopology, beginFileUpload and getNimbusConf. Until the upgrade, Apache advises populating nimbus.users with the intended principals. After upgrading, a group-only configuration becomes restrictive for the first time. The 9.8 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.