Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-82432

Apache Storm Nimbus: blobstore authorization bypass through rebalance overrides

Technology

Apache Storm

CVSS Score

8.1 / 10.0

Affected Versions

Apache Storm 3.0.0

Upstream Fix

3.1.0

Published

September 14, 2026

OSSeva Coverage

Fixed upstream

Description

Nimbus validated topology.blobstore.map against the caller only at submission, so a user allowed to rebalance a topology could add a blob they have no access to and have supervisors localise it. listBlobs also skipped authorization and returned every key in the blobstore. Membership of topology.users or topology.groups confers rebalance rights. The 8.1 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 3.0.0, you need this patch. Book a discovery call to get covered.