CVE-2026-82431
Apache Storm: nimbus.groups ignored when nimbus.users is empty
Technology
Apache Storm
CVSS Score
9.8 / 10.0
Affected Versions
Apache Storm 3.0.0
Upstream Fix
3.1.0
Published
September 14, 2026
OSSeva Coverage
Fixed upstream
Description
SimpleACLAuthorizer returned early when nimbus.users was empty, before nimbus.groups was considered, so a cluster restricted by group alone had no restriction: every authenticated principal could perform every user-level operation, including submitTopology, beginFileUpload and getNimbusConf. Until the upgrade, Apache advises populating nimbus.users with the intended principals. After upgrading, a group-only configuration becomes restrictive for the first time. The 9.8 score on NVD is from CISA-ADP.
Is your Apache Storm deployment affected?
If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.