Junglewise Threat Intelligence

CVE-2026-82430: Concord worker-launcher privilege escalation in Docker/OCI worker isolation

CVE-2026-82430 · Severity: high · CVSS 7.8 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Concord's worker-launcher is a privileged system component that manages Docker and OCI container execution for workflow tasks. A race condition allows untrusted users to rewrite configuration files after the launcher grants them directory ownership but before it reads the command file, enabling arbitrary container execution as root with full host filesystem access or execution as other users' accounts.

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in the setuid-root worker-launcher. The launcher changes ownership of the worker directory to an untrusted user, then reads a command file from that directory without the O_NOFOLLOW flag or post-open ownership verification. An attacker can replace the command file contents during this window. For Docker, the parsed command is executed as real uid 0 with insufficient sanitization (permit-lists allow `-v`, `--device`, `--cap-add`, etc.), yielding root-equivalent container invocation with host filesystem access. For OCI, arbitrary bind-mounts are permitted without source/destination validation, and the username field can be set to another tenant's uid. Fix: upgrade to version 3.1.0, which validates and re-verifies the command file before the ownership change and constrains mounts by configuration.

Affected products

  • Apache Concord before 3.1.0

Timeline

  • 2026-09-14: disclosed