Junglewise Threat Intelligence

CVE-2026-82427: Apache Storm path traversal in blobstore symlink creation

CVE-2026-82427 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apache Storm. Vendors: Apache.

Executive brief

Apache Storm is a distributed stream processing system used to process large volumes of data in real-time. An attacker with topology submission privileges could exploit a path traversal vulnerability in the blobstore configuration to delete arbitrary supervisor-owned files or create malicious symlinks that allow code execution as another user, bypassing the intended tenant isolation.

Technical details

The vulnerability exists in Storm's `AsyncLocalizer` and `Container.createBlobstoreLinks` components, which fail to normalize the `topology.blobstore.map` configuration. An attacker can craft a topology containing path traversal sequences (e.g., `../`) in blob names to direct delete-and-symlink operations at arbitrary paths on the supervisor node. Because the symlink creation forcibly deletes existing files before creating the link, an attacker can recursively delete supervisor-owned content or plant symlinks that cause subsequent worker processes to execute arbitrary code as a different tenant user. The attack requires topology submission privileges and affects all nodes where the topology is scheduled. A fix was released in version 3.1.0 that enforces path normalization checks at both call sites.

Affected products

  • Apache Storm before 3.1.0

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fix available in version 3.1.0

References

Related threats